CVE-2017-17103: Fiyo CMS

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from normal user privileges to administrator privileges.

Affected products

  • Fiyo Fiyo CMS: version 2.0.7 only

Published 2017-12-04. Last modified 2026-06-17.