Vulnerability Description
SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yiiframework | Yii | >= 2.0.0, <= 2.0.47 |
Related Weaknesses (CWE)
References
- https://github.com/yiisoft/yii2/issues/19755ExploitIssue Tracking
- https://github.com/yiisoft/yii2/issues/19755#issuecomment-1426155955
- https://github.com/yiisoft/yii2/issues/19755#issuecomment-1505390813
- https://github.com/yiisoft/yii2/issues/19755#issuecomment-1505560351
- https://github.com/yiisoft/yii2/issues/19755ExploitIssue Tracking
- https://github.com/yiisoft/yii2/issues/19755#issuecomment-1426155955
- https://github.com/yiisoft/yii2/issues/19755#issuecomment-1505390813
- https://github.com/yiisoft/yii2/issues/19755#issuecomment-1505560351
FAQ
What is CVE-2023-26750?
CVE-2023-26750 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's po...
How severe is CVE-2023-26750?
CVE-2023-26750 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-26750?
Check the references section above for vendor advisories and patch information. Affected products include: Yiiframework Yii.