ZeroHour

CVE-2024-58136

KEV PoC large1

Regression of Yii 2 Behavior-Attachment Flaw (CVE-2024-4990) Enables In-the-Wild RCE

CISA: Yiiframework Yii Improper Protection of Alternate Path Vulnerability

CVSS 3.1
9.8 critical
EPSS
88%p100
Published
()
KEV added
AI analysis

Yii 2 versions before 2.0.52 mishandle the attaching of behaviors defined with an __class array key, reintroducing the flaw fixed for CVE-2024-4990, an unauthenticated remote code execution issue (CWE-424, improper protection of alternate path). The defect is triggered remotely without authentication when a vulnerable application attaches behaviors this way, giving an attacker high-impact code execution (CVSS 9.8). Any application built on a vulnerable Yii 2 release is affected, most prominently Craft CMS sites, which were the target of an observed in-the-wild campaign between February and April 2025. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-02, carries an 84.6% EPSS probability of exploitation within 30 days, and a public SensePost writeup documents the active Craft CMS exploitation campaign. The top headline reports that hundreds of servers were likely compromised in that campaign.

What to do: Upgrade Yii 2 to version 2.0.52 or later; Craft CMS operators should immediately update Craft CMS to its patched release that bundles fixed Yii, and confirm the resolved framework version on the system. Because the campaign ran from February through April 2025, review web/application logs and hosted files for indicators from the SensePost writeup, treating any unpatched internet-facing Yii 2 or Craft CMS host as likely compromised. Federal agencies must apply the KEV required action (vendor mitigations or BOD 22-01 guidance) by the CISA deadline.

Affected
yiiframework yiiYii 2, all versions before 2.0.52
Estimated exposure
large≈100,000+ internet-facing applications built on Yii 2 (including tens of thousands of Craft CMS sites) — Yii 2 is one of the most widely installed PHP frameworks (hundreds of millions of Packagist downloads across countless custom apps), and Craft CMS, its most prominent downstream application, accounts for tens of thousands of public sites…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

CISA Known Exploited Vulnerability
Affected
Yiiframework Yii
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
yiiframework
Products
yii
Weakness
CWE-424
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news