CVE-2017-11417 is a critical SQL injection vulnerability affecting Fiyo CMS version 2.0.7, specifically within the 'dapur/apps/app_article/controller/article_status.php' component via the 'id' parameter. With a CVSS score of 9.8, this flaw allows unauthenticated attackers to remotely execute arbitrary SQL commands, leading to complete compromise of confidentiality, integrity, and availability. While there are no known public exploits in Metasploit or ExploitDB, the vulnerability has garnered significant community discussion, indicating potential interest in developing exploits. Despite its age, the high FAUCET Risk Score of 92/100 suggests it remains a significant threat if unpatched.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.7CPE matchmatch criteria | cpe:2.3:a:fiyo:fiyo_cms:2.0.7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.