First published: Sat Jan 21 2023(Updated: )
Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yiiframework Gii | <2.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-36655.
The severity of CVE-2020-36655 is high (8.8).
CVE-2020-36655 allows remote attackers to execute arbitrary code by embedding PHP code into the model file through the Generator.php messageCategory field.
Yii2 Gii before version 2.2.2 is affected by CVE-2020-36655.
To fix CVE-2020-36655, upgrade to Yii2 Gii version 2.2.2 or newer.