Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-47130

Опубликовано: 14 нояб. 2023
Источник: debian
EPSS Низкий

Описание

Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. An attacker may leverage this vulnerability to compromise the host system. A fix has been developed for the 1.1.29 release. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
yiiitppackage

EPSS

Процентиль: 87%
0.03255
Низкий

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 лет назад

Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. An attacker may leverage this vulnerability to compromise the host system. A fix has been developed for the 1.1.29 release. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.1
github
около 2 лет назад

yiisoft/yii deserializing untrusted user input can lead to remote code execution

EPSS

Процентиль: 87%
0.03255
Низкий