CVE-2023-26750: SQL Injection
DISPUTED SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.
Other sources
Withdrawn Advisory This advisory has been withdrawn because the issue originates from a product built on Yii2, not the Yii2 Framework itself. This link is maintained to preserve external references.
Original Description SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-26750?
CVE-2023-26750 is a SQL injection vulnerability found in Yii Framework Yii 2 before version 2.0.47.
How severe is CVE-2023-26750?
CVE-2023-26750 has a severity rating of 9.8 (Critical).
Which software is affected by CVE-2023-26750?
Yii Framework Yii 2 before version 2.0.47 and Yiiframework Yii are affected by CVE-2023-26750.
How can I fix CVE-2023-26750?
To fix CVE-2023-26750, update to Yii Framework Yii 2 version 2.0.47 or later.
Where can I find more information about CVE-2023-26750?
You can find more information about CVE-2023-26750 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-26750), [GitHub Issue](https://github.com/yiisoft/yii2/issues/19755), [GitHub Comment](https://github.com/yiisoft/yii2/issues/19755#issuecomment-1426155955).