CRITICAL9.8
GHSA-hhg2-g6h6-c266
Yii SQL injection vulnerability
Quick fix
GHSA-hhg2-g6h6-c266 — yiisoft/yii2-dev: upgrade to the fixed version with the command below.
composer require yiisoft/yii2-dev:^2.0.12.1Details
The findByCondition function in `framework/db/ActiveRecord.php` in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/yiisoft/yii2-dev
Introduced in:
0Fixed in: 2.0.12.1Fix
composer require yiisoft/yii2-dev:^2.0.12.1Packagist/yiisoft/yii2-dev
Introduced in:
2.0.13Fixed in: 2.0.13.2Fix
composer require yiisoft/yii2-dev:^2.0.13.2Packagist/yiisoft/yii2-dev
Introduced in:
2.0.14Fixed in: 2.0.15Fix
composer require yiisoft/yii2-dev:^2.0.15References
- https://nvd.nist.gov/vuln/detail/CVE-2018-7269[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/yiisoft/yii2-dev/CVE-2018-7269.yaml[WEB]
- https://github.com/yiisoft/yii2[PACKAGE]
- https://www.yiiframework.com/news/168/releasing-yii-2-0-15-and-database-extensions-with-security-fixes[WEB]