Executive brief
Yot CMS, a web-based content management system, is vulnerable to a security flaw that allows unauthorized individuals to access its underlying database. By sending specially crafted web requests, an attacker can steal sensitive information such as user credentials, site configuration, and private content. This could lead to a full compromise of the website and its data without requiring any login credentials.
Technical details
An SQL injection vulnerability exists in Yot CMS 3.3.1 within the index.php component. The application fails to properly sanitize the 'aid' and 'cid' GET parameters before using them in SQL queries. An unauthenticated remote attacker can exploit this by sending crafted GET requests to index.php (specifically when the 'page' parameter is set to 'articles'), allowing for the execution of arbitrary SQL commands. This can be used to extract sensitive database information, including table structures and administrative data. The vulnerability was publicly disclosed with proof-of-concept exploits available on Exploit-DB.
Affected products
- Yot Yot CMS 3.3.1
Timeline
- 2018-11-01: disclosed: Initial discovery and exploit publication by Ihsan Sencan
- 2026-05-30: advisory: CVE-2018-25425 published to the NVD dataset