Vulnerabilidad · Publicado 14/09/2026
Se identificó una vulnerabilidad de inyección SQL en el manejador de cookies de Yot CMS versión 3.3.1 y anteriores. El parámetro yot3_user/yot3_pass en la función Login del archivo global.php permite ataques remotos sin autenticación. El exploit público incrementa el riesgo para sitios web y portales corporativos en LATAM que usan esta plataforma.
A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file global.php of the component Cookie Handler. This manipulation of the argument yot3_user/yot3_pass causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Score: 7.3/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-74, CWE-89
Publicado en NIST NVD.