PT-2026-91170 · Yot Cms · Yot Cms
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Yot CMS versions prior to 3.3.2
Description
A remote SQL injection exists within the Cookie Handler component. The issue occurs in the
Login() function located in the global.php file when processing the yot3 user and yot3 pass arguments. SQL injection is a technique where an attacker inserts malicious SQL code into a query, allowing them to manipulate the database.Recommendations
Update Yot CMS to version 3.3.2 or later.
As a temporary workaround, restrict access to the
Login() function in the global.php file.Exploit
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Yot Cms