First published: Tue Apr 04 2023(Updated: )
** DISPUTED ** SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/yiisoft/yii2 | <2.0.47 | 2.0.47 |
Yii Framework | >=2.0.0<=2.0.47 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26750 is a SQL injection vulnerability found in Yii Framework Yii 2 before version 2.0.47.
CVE-2023-26750 has a severity rating of 9.8 (Critical).
Yii Framework Yii 2 before version 2.0.47 and Yiiframework Yii are affected by CVE-2023-26750.
To fix CVE-2023-26750, update to Yii Framework Yii 2 version 2.0.47 or later.
You can find more information about CVE-2023-26750 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-26750), [GitHub Issue](https://github.com/yiisoft/yii2/issues/19755), [GitHub Comment](https://github.com/yiisoft/yii2/issues/19755#issuecomment-1426155955).