VDB
Sign up
CRITICAL9.8

GHSA-hhg2-g6h6-c266

Yii SQL injection vulnerability

Quick fix

GHSA-hhg2-g6h6-c266 — yiisoft/yii2-dev: upgrade to the fixed version with the command below.

composer require yiisoft/yii2-dev:^2.0.12.1

Details

The findByCondition function in `framework/db/ActiveRecord.php` in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/yiisoft/yii2-dev
Introduced in: 0Fixed in: 2.0.12.1
Fixcomposer require yiisoft/yii2-dev:^2.0.12.1
Packagist/yiisoft/yii2-dev
Introduced in: 2.0.13Fixed in: 2.0.13.2
Fixcomposer require yiisoft/yii2-dev:^2.0.13.2
Packagist/yiisoft/yii2-dev
Introduced in: 2.0.14Fixed in: 2.0.15
Fixcomposer require yiisoft/yii2-dev:^2.0.15

References