High severity8.8NVD Advisory· Published Dec 4, 2017· Updated May 13, 2026
CVE-2017-17103
CVE-2017-17103
Description
Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from normal user privileges to administrator privileges.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/FiyoCMS/FiyoCMS/issues/10nvdExploitIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.