cve.akaoma.com
SQL Injection Vulnerabilities Discovered in Gate Pass Management System and Yot CMS
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Two critical SQL injection vulnerabilities have been identified in Gate Pass Management System 2.1 and Yot CMS 3.3.1, both published on 2026-05-30. CVE-2018-25424 allows unauthenticated attackers to bypass authentication via the login-exec.php endpoint, while CVE-2018-25425 enables attackers to execute arbitrary SQL queries through the aid and cid parameters of index.php. Both vulnerabilities can lead to unauthorized access and data extraction. No public proof-of-concept or evidence of exploitation has been reported yet. Security professionals are urged to implement patches and protective measures. The CVSS base score for both vulnerabilities is 8.2, indicating a high severity level. Immediate action is recommended to mitigate potential risks.
Key Points: • CVE-2018-25424 and CVE-2018-25425 are critical SQL injection vulnerabilities. • Both vulnerabilities allow unauthenticated attackers to access sensitive data. • Patches are available for CVE-2018-25425; urgent action is recommended for both vulnerabilities.