ZeroHour

CVE-2020-36655

PoC ×2
CVSS 3.1
8.8 high
EPSS
1%p72
Published
()
Modified
Description

Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.

Vendors
yiiframework
Products
gii
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.