A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Yot CMS Admin Console admin.php eval code injection
Problem type
Affected products
Yot
3.3.0 - AFFECTED
3.3.1 - AFFECTED
References
https://vuldb.com/vuln/403251
https://vuldb.com/vuln/403251/cti
https://vuldb.com/cve/CVE-2026-90709
https://vuldb.com/submit/918371
https://github.com/dddwmr/CVE/blob/main/YOT%20III%20modsys%3Aconsole%20admin%20eval%20of%20POST%20text%20leads%20to%20remote%20code%20execution.md
GitHub Security Advisories
GHSA-cjwg-q7rf-chx4
A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the...
https://github.com/advisories/GHSA-cjwg-q7rf-chx4A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
https://nvd.nist.gov/vuln/detail/CVE-2026-90709
https://github.com/dddwmr/CVE/blob/main/YOT%20III%20modsys%3Aconsole%20admin%20eval%20of%20POST%20text%20leads%20to%20remote%20code%20execution.md
https://vuldb.com/cve/CVE-2026-90709
https://vuldb.com/submit/918371
https://vuldb.com/vuln/403251
https://vuldb.com/vuln/403251/cti
https://github.com/advisories/GHSA-cjwg-q7rf-chx4
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-90709Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-90709",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-09-14T11:41:16.401Z",
"dateReserved": "2026-09-13T08:22:05.649Z",
"datePublished": "2026-09-14T11:15:07.285Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-09-14T11:15:07.285Z"
},
"title": "Yot CMS Admin Console admin.php eval code injection",
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used."
}
],
"affected": [
{
"vendor": "Yot",
"product": "CMS",
"cpes": [
"cpe:2.3:a:yot:cms:*:*:*:*:*:*:*:*"
],
"modules": [
"Admin Console"
],
"versions": [
{
"version": "3.3.0",
"status": "affected"
},
{
"version": "3.3.1",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Code Injection",
"cweId": "CWE-94",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Injection",
"cweId": "CWE-74",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/vuln/403251",
"name": "VDB-403251 | Yot CMS Admin Console admin.php eval code injection",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/vuln/403251/cti",
"name": "VDB-403251 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/cve/CVE-2026-90709",
"name": "CVE-2026-90709 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://vuldb.com/submit/918371",
"name": "Submit #918371 | Yot Content Management System 3.3.1 console admin eval of POST text leads to remote code execution",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://github.com/dddwmr/CVE/blob/main/YOT%20III%20modsys%3Aconsole%20admin%20eval%20of%20POST%20text%20leads%20to%20remote%20code%20execution.md",
"tags": [
"exploit"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 4.7,
"baseSeverity": "MEDIUM"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 4.7,
"baseSeverity": "MEDIUM"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"baseScore": 5.8
}
}
],
"timeline": [
{
"time": "2026-09-13T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-09-13T02:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-09-13T10:27:16.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "dwmm (VulDB User)",
"type": "reporter"
}
]
},
"adp": [
{
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2026-09-14T11:41:16.401Z"
},
"title": "CISA ADP Vulnrichment",
"metrics": [
{}
]
}
]
}
}