Description
Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. An attacker may leverage this vulnerability to compromise the host system. A fix has been developed for the 1.1.29 release. Users are advised to upgrade. There are no known workarounds for this vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3001 | Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. An attacker may leverage this vulnerability to compromise the host system. A fix has been developed for the 1.1.29 release. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-mw2w-2hj2-fg8q | yiisoft/yii deserializing untrusted user input can lead to remote code execution |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-14T19:26:42.011Z
Reserved: 2023-10-30T19:57:51.677Z
Link: CVE-2023-47130
Updated: 2024-08-02T21:01:22.829Z
Status : Modified
Published: 2023-11-14T21:15:11.450
Modified: 2024-11-21T08:29:50.493
Link: CVE-2023-47130
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA