Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gq63-p39p-jrjf

Опубликовано: 04 апр. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Withdrawn: SQL injection in Yii 2

Withdrawn Advisory

This advisory has been withdrawn because the issue originates from a product built on Yii2, not the Yii2 Framework itself. This link is maintained to preserve external references.

Original Description

SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function.

Пакеты

Наименование

yiisoft/yii2

composer
Затронутые версииВерсия исправления

< 2.0.47

2.0.47

EPSS

Процентиль: 91%
0.06643
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-79
CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
почти 3 года назад

SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.

CVSS3: 9.8
debian
почти 3 года назад

SQL injection vulnerability found in Yii Framework Yii 2 Framework bef ...

EPSS

Процентиль: 91%
0.06643
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-79
CWE-89