First published: Wed Nov 23 2022(Updated: )
`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Yiiframework Yii | <1.1.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
`CVE-2022-41922` is a vulnerability in `yiisoft/yii` before version `1.1.27` that allows remote code execution if the application calls `unserialize()` on arbitrary user input.
The severity of `CVE-2022-41922` is critical, with a CVSS score of `9.8`.
`CVE-2022-41922` affects `yiisoft/yii` before version `1.1.27`.
To fix `CVE-2022-41922`, update `yiisoft/yii` to version `1.1.27` or later.
You can find more information about `CVE-2022-41922` on the GitHub commit page (link: [https://github.com/yiisoft/yii/commit/ed67b7cc57216557c5c595c6650cdd2d3aa41c52]) and the GitHub security advisories page (link: [https://github.com/yiisoft/yii/security/advisories/GHSA-442f-wcwq-fpcf]).