SQL Injection Vulnerability in YzmCMS by YzmCMS
CVE-2026-75417
7.2HIGH
What is CVE-2026-75417?
A SQL injection flaw exists in YzmCMS version 7.5, specifically in the get_arrchildid() function located in application/admin/controller/category.class.php. This vulnerability arises due to the lack of proper input sanitization when handling the user-controllable parentid parameter. By exploiting this, an authenticated administrator can craft arbitrary SQL commands through boolean-based blind injection techniques, which could lead to a complete compromise of the database, exposing sensitive information and integrity issues.
