Description
A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file global.php of the component Cookie Handler. This manipulation of the argument yot3_user/yot3_pass causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass and privilege escalation via SQL injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the Login function of global.php in Yot CMS’s Cookie Handler. When the yot3_user and yot3_pass arguments are supplied, they are concatenated directly into an SQL query, allowing an attacker to inject arbitrary SQL code. An attacker can craft a payload that changes the authentication logic so that valid credentials are not required, effectively forging administrator sessions. This is an input‑validation weakness identified as CWE‑74 and results in unexpected control flow, which, due to the nature of the login query, enables privilege escalation.

Affected Systems

All installations of Yot CMS with version 3.3.1 or earlier are affected. The vulnerability resides in the Cookie Handler component of the CMS system and applies to the global.php Login endpoint.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog a public exploit has been released, suggesting realistic exploitation potential. The risk is therefore moderate but realized because the flaw directly impacts authentication integrity.

Generated by OpenCVE AI on September 15, 2026 at 14:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Yot CMS to a release newer than 3.3.1, which removes the vulnerable Login logic.
  • If an immediate upgrade is not feasible, implement input sanitation on the yot3_user and yot3_pass fields by using parameterized queries or escaping to eliminate the SQL injection vector.
  • Restrict access to the login endpoint by limiting IP ranges or applying firewall rules to reduce the attack surface.

Generated by OpenCVE AI on September 15, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file global.php of the component Cookie Handler. This manipulation of the argument yot3_user/yot3_pass causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Title Yot CMS Cookie global.php login sql injection
First Time appeared Yot
Yot cms
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:yot:cms:*:*:*:*:*:*:*:*
Vendors & Products Yot
Yot cms
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T16:00:59.537Z

Reserved: 2026-09-13T08:22:02.047Z

Link: CVE-2026-90708

cve-icon Vulnrichment

Updated: 2026-09-15T16:00:56.443Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T11:17:07.313

Modified: 2026-09-15T17:17:38.973

Link: CVE-2026-90708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T10:00:13Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')