Impact
A vulnerability in Yot CMS up to version 3.3.1 allows an attacker to inject malicious code through the eval call in modsys/console/admin.php. The weakness originates from improper handling of the POST parameter "text", leading to CWE-74 (Improper Neutralization of Input During Web Page Generation) and CWE-94 (Improper) attacker supplies arbitrary code, which can be executed on the server with the privileges of the web application, compromising confidentiality, integrity, and availability.
Affected Systems
Installations of Yot CMS versions up to and including 3.3.1 are affected. The flaw exists in the Admin Console component’s admin.php script where an eval function processes user-supplied input. No patch, update, or workaround is described in the advisory; the references only document the presence of the vulnerability.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity vulnerability. Exploitation is possible remotely, as the attack can be launched against the admin console. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog. Despite the moderate score, an attacker could achieve full system compromise if the admin console is exposed to the internet or an untrusted network segment.
OpenCVE Enrichment