VDB
Sign up
HIGH

GHSA-74qv-rv53-5wcx

Yii PHP Framework arbitrary PHP scripts execution

Quick fix

GHSA-74qv-rv53-5wcx — yiisoft/yii: upgrade to the fixed version with the command below.

composer require yiisoft/yii:^1.1.15

Details

The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value property.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/yiisoft/yii
Introduced in: 1.1.14Fixed in: 1.1.15
Fixcomposer require yiisoft/yii:^1.1.15

References