top of page
perceptive_background_267k.jpg

A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/admin/controller/category.class.php,…

Published:

28 augustus 2026 om 00:00:00

Alert date:

28 augustus 2026 om 23:18:32

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

A SQL injection vulnerability has been identified in YzmCMS version 7.5, tracked as CVE-2026-75417. The vulnerability exists in the get_arrchildid() function located in application/admin/controller/category.class.php. The flaw arises from unsanitized concatenation of the user-controlled parentid parameter directly into a FIND_IN_SET() SQL clause. An authenticated administrator can exploit this vulnerability to perform boolean-based blind SQL injection attacks. Successful exploitation could allow arbitrary SQL query execution against the backend database. The potential impact includes full database compromise, including reading, modifying, or deleting sensitive data. A proof-of-concept (PoC) has been published on GitHub, increasing the risk of active exploitation. The vulnerability requires authentication, limiting the attack surface to admin-level users.

Technical details

Mitigation steps:

Affected products:

YzmCMS 7.5

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page