VDB
Sign up
HIGH8.8

GHSA-3mpg-q26j-83j5

Command injection in yiisoft/yii2-gii

Quick fix

GHSA-3mpg-q26j-83j5 — yiisoft/yii2-gii: upgrade to the fixed version with the command below.

composer require yiisoft/yii2-gii:^2.2.2

Details

Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/yiisoft/yii2-gii
Introduced in: 0Fixed in: 2.2.2
Fixcomposer require yiisoft/yii2-gii:^2.2.2

References