PT-2020-6845 · Yii2 Gii · Yii2 Gii

D90Pwn

·

Published

2020-05-08

·

Updated

2023-01-30

·

CVE-2020-36655

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Yii2 Gii versions prior to 2.2.2
Description The issue allows remote attackers to execute arbitrary code via the messageCategory field in Generator.php. This can be done by embedding arbitrary PHP code into the model file. The vulnerability is related to the restoration of an invalid data structure in memory, which can be exploited by a remote attacker to execute arbitrary code.
Recommendations For versions prior to 2.2.2, update to version 2.2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Generator.php file and the messageCategory field to minimize the risk of exploitation.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2023-00799
CVE-2020-36655
GHSA-3MPG-Q26J-83J5

Affected Products

Yii2 Gii