Impact
The vulnerability exists in the Login function of global.php in Yot CMS’s Cookie Handler. When the yot3_user and yot3_pass arguments are supplied, they are concatenated directly into an SQL query, allowing an attacker to inject arbitrary SQL code. An attacker can craft a payload that changes the authentication logic so that valid credentials are not required, effectively forging administrator sessions. This is an input‑validation weakness identified as CWE‑74 and results in unexpected control flow, which, due to the nature of the login query, enables privilege escalation.
Affected Systems
All installations of Yot CMS with version 3.3.1 or earlier are affected. The vulnerability resides in the Cookie Handler component of the CMS system and applies to the global.php Login endpoint.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog a public exploit has been released, suggesting realistic exploitation potential. The risk is therefore moderate but realized because the flaw directly impacts authentication integrity.
OpenCVE Enrichment