2026-09-14 11:15CVE-2026-90709VulDB
PUBLISHED5.2ApplicationCWE-94CWE-74

Yot CMS Admin Console admin.php eval code injection

A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

Problem type

Affected products

Yot

CMS

3.3.0 - AFFECTED

3.3.1 - AFFECTED

References

GitHub Security Advisories

GHSA-cjwg-q7rf-chx4

A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the...

https://github.com/advisories/GHSA-cjwg-q7rf-chx4

A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-90709
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-90709",
    "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
    "assignerShortName": "VulDB",
    "dateUpdated": "2026-09-14T11:41:16.401Z",
    "dateReserved": "2026-09-13T08:22:05.649Z",
    "datePublished": "2026-09-14T11:15:07.285Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "shortName": "VulDB",
        "dateUpdated": "2026-09-14T11:15:07.285Z"
      },
      "title": "Yot CMS Admin Console admin.php eval code injection",
      "descriptions": [
        {
          "lang": "en",
          "value": "A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used."
        }
      ],
      "affected": [
        {
          "vendor": "Yot",
          "product": "CMS",
          "cpes": [
            "cpe:2.3:a:yot:cms:*:*:*:*:*:*:*:*"
          ],
          "modules": [
            "Admin Console"
          ],
          "versions": [
            {
              "version": "3.3.0",
              "status": "affected"
            },
            {
              "version": "3.3.1",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Code Injection",
              "cweId": "CWE-94",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Injection",
              "cweId": "CWE-74",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://vuldb.com/vuln/403251",
          "name": "VDB-403251 | Yot CMS Admin Console admin.php eval code injection",
          "tags": [
            "vdb-entry",
            "technical-description"
          ]
        },
        {
          "url": "https://vuldb.com/vuln/403251/cti",
          "name": "VDB-403251 | CTI Indicators (IOB, IOC, TTP, IOA)",
          "tags": [
            "signature",
            "permissions-required"
          ]
        },
        {
          "url": "https://vuldb.com/cve/CVE-2026-90709",
          "name": "CVE-2026-90709 | CVE Analysis and Report",
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://vuldb.com/submit/918371",
          "name": "Submit #918371 | Yot Content Management System 3.3.1 console admin eval of POST text leads to remote code execution",
          "tags": [
            "third-party-advisory"
          ]
        },
        {
          "url": "https://github.com/dddwmr/CVE/blob/main/YOT%20III%20modsys%3Aconsole%20admin%20eval%20of%20POST%20text%20leads%20to%20remote%20code%20execution.md",
          "tags": [
            "exploit"
          ]
        }
      ],
      "metrics": [
        {},
        {
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM"
          }
        },
        {
          "cvssV3_0": {
            "version": "3.0",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM"
          }
        },
        {
          "cvssV2_0": {
            "version": "2.0",
            "vectorString": "AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
            "baseScore": 5.8
          }
        }
      ],
      "timeline": [
        {
          "time": "2026-09-13T00:00:00.000Z",
          "lang": "en",
          "value": "Advisory disclosed"
        },
        {
          "time": "2026-09-13T02:00:00.000Z",
          "lang": "en",
          "value": "VulDB entry created"
        },
        {
          "time": "2026-09-13T10:27:16.000Z",
          "lang": "en",
          "value": "VulDB entry last update"
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "dwmm (VulDB User)",
          "type": "reporter"
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-09-14T11:41:16.401Z"
        },
        "title": "CISA ADP Vulnrichment",
        "metrics": [
          {}
        ]
      }
    ]
  }
}