CVE-2020-36655
PoC ×2—CVSS 3.1
8.8 high
EPSS
1%p72
Published
()
Modified
Description
Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.
- Vendors
- yiiframework
- Products
- gii
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.