SQL Injection Vulnerabilities Discovered in Gate Pass Management System and Yot CMS

SQL Injection Vulnerabilities Discovered in Gate Pass Management System and Yot CMS

First seen 30 May 2026, 23:21 UTC Feedlywww.incibe.escve.akaoma.comvulners.comvuldb.com 91% similarity 74.0

Article Content

Browse articles
ThreatCluster

Two critical SQL injection vulnerabilities have been identified in Gate Pass Management System 2.1 and Yot CMS 3.3.1, both published on 2026-05-30. CVE-2018-25424 allows unauthenticated attackers to bypass authentication via the login-exec.php endpoint, while CVE-2018-25425 enables attackers to execute arbitrary SQL queries through the aid and cid parameters of index.php. Both vulnerabilities can lead to unauthorized access and data extraction. No public proof-of-concept or evidence of exploitation has been reported yet. Security professionals are urged to implement patches and protective measures. The CVSS base score for both vulnerabilities is 8.2, indicating a high severity level. Immediate action is recommended to mitigate potential risks.

Key Points: • CVE-2018-25424 and CVE-2018-25425 are critical SQL injection vulnerabilities. • Both vulnerabilities allow unauthenticated attackers to access sensitive data. • Patches are available for CVE-2018-25425; urgent action is recommended for both vulnerabilities.

ThreatCluster AI How this analysis works

Timeline

2026-05-30
CVE-2018-25424 published
Gate Pass Management System 2.1 has an SQL injection vulnerability allowing unauthenticated access.
Feedly
2026-05-30
CVE-2018-25425 published
Yot CMS 3.3.1 contains an SQL injection vulnerability enabling data extraction via crafted GET requests.
Feedly
2026-05-30
Security advisories released
GitHub Advisories published patches for CVE-2018-25425; mitigation steps recommended for both vulnerabilities.
Feedly
2026-05-30
INCIBE-CERT alerts issued
INCIBE-CERT confirmed the vulnerabilities and their high severity ratings, urging immediate action.
www.incibe.es
2026-05-31
Urgent mitigation recommended
Cybersecurity professionals classify both vulnerabilities as immediate threats requiring urgent mitigation actions.
cve.akaoma.com

Community

Browse all →

Tracked Entities in This Story