CVE-2014-9148: Fiyo CMS

Critical severity, CVSS 9.8. EPSS: 11.4% chance of exploitation in the next 30 days.

Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.

Affected products

  • Fiyo Fiyo CMS: up to and including 2.0.1.8

Published 2017-10-16. Last modified 2026-06-17.