Vulnerability Details CVE-2014-9148
Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.242
EPSS Ranking 95.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2014-9148
-
cpe:2.3:a:fiyo:fiyo_cms:1.5.7
-
cpe:2.3:a:fiyo:fiyo_cms:2.0
-
cpe:2.3:a:fiyo:fiyo_cms:2.0.1.5
-
cpe:2.3:a:fiyo:fiyo_cms:2.0.1.6
-
cpe:2.3:a:fiyo:fiyo_cms:2.0.1.7
-
cpe:2.3:a:fiyo:fiyo_cms:2.0.1.8