Description
A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in Yot CMS up to version 3.3.1 allows an attacker to inject malicious code through the eval call in modsys/console/admin.php. The weakness originates from improper handling of the POST parameter "text", leading to CWE-74 (Improper Neutralization of Input During Web Page Generation) and CWE-94 (Improper) attacker supplies arbitrary code, which can be executed on the server with the privileges of the web application, compromising confidentiality, integrity, and availability.

Affected Systems

Installations of Yot CMS versions up to and including 3.3.1 are affected. The flaw exists in the Admin Console component’s admin.php script where an eval function processes user-supplied input. No patch, update, or workaround is described in the advisory; the references only document the presence of the vulnerability.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity vulnerability. Exploitation is possible remotely, as the attack can be launched against the admin console. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog. Despite the moderate score, an attacker could achieve full system compromise if the admin console is exposed to the internet or an untrusted network segment.

Generated by OpenCVE AI on September 15, 2026 at 14:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Yot CMS patch or upgrade to a version that removes the vulnerable eval call
  • If upgrade is not feasible, restrict access to the admin console to trusted IPs or over a VPN and block or filter POST requests that contain executable code patterns
  • Implement input validation or sanitization on the "text" parameter to prevent code execution, or replace the eval functionality with a safer alternative

Generated by OpenCVE AI on September 15, 2026 at 14:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Title Yot CMS Admin Console admin.php eval code injection
First Time appeared Yot
Yot cms
Weaknesses CWE-74
CWE-94
CPEs cpe:2.3:a:yot:cms:*:*:*:*:*:*:*:*
Vendors & Products Yot
Yot cms
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T11:41:16.401Z

Reserved: 2026-09-13T08:22:05.649Z

Link: CVE-2026-90709

cve-icon Vulnrichment

Updated: 2026-09-14T11:41:12.454Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T12:17:50.830

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90709

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:00:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')