{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/yot-cms--3.3.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:yot:cms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90708"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Yot CMS (\u003c= 3.3.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Yot"],"content_html":"\u003cp\u003eYot CMS versions up to 3.3.1 are vulnerable to a SQL injection vulnerability (CVE-2026-90708) located in the Login function within the global.php file of the Cookie Handler component. The vulnerability arises from improper sanitization of the yot3_user and yot3_pass arguments. Attackers can trigger this vulnerability remotely by sending malicious HTTP requests containing SQL injection payloads to the application. Public exploit code for this vulnerability is available, increasing the risk of exploitation. Defenders should treat this as a high-priority risk for internet-facing installations of Yot CMS and consider implementation of input validation controls or upgrading the software if a patch is available.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing Yot CMS instances.\u003c/li\u003e\n\u003cli\u003eAttacker locates the application login page or cookie handling logic.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting the Login function in global.php.\u003c/li\u003e\n\u003cli\u003eAttacker inserts malicious SQL syntax into the yot3_user or yot3_pass cookie arguments.\u003c/li\u003e\n\u003cli\u003eThe server-side application fails to sanitize these inputs and passes them to the database query.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected SQL commands, potentially leading to unauthorized data access, credential theft, or bypass of authentication.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized access to the backend database. This may lead to the exfiltration of sensitive information, including user credentials or session data, and in some configurations, could result in administrative account compromise or complete control over the CMS instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify all instances of Yot CMS (\u0026lt;= 3.3.1) in your environment.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect and block HTTP requests containing SQL injection patterns directed at the Login function or global.php.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for anomalies in the 'yot3_user' or 'yot3_pass' parameters.\u003c/li\u003e\n\u003cli\u003eCoordinate with IT operations to patch or upgrade Yot CMS to a version beyond 3.3.1.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-14T11:33:25Z","date_published":"2026-09-14T11:33:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-yot-cms-sqli/","summary":"An unauthenticated remote SQL injection vulnerability in Yot CMS versions up to 3.3.1 allows attackers to execute arbitrary database commands via the Login function.","title":"SQL Injection in Yot CMS Cookie Handler","url":"https://feed.craftedsignal.io/briefs/2026-09-yot-cms-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Yot CMS (\u003c= 3.3.1)","version":"https://jsonfeed.org/version/1.1"}