CVE-2023-47130
Unsafe deserialization of user data in yiisoft/yii
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. An attacker may leverage this vulnerability to compromise the host system. A fix has been developed for the 1.1.29 release. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Yii es un framework web PHP de código abierto. yiisoft/yii antes de la versión 1.1.29 son vulnerables a Remote Code Execution (RCE) si la aplicación llama a `unserialize()` ante una entrada arbitraria del usuario. Un atacante puede aprovechar esta vulnerabilidad para comprometer el sistema host. Se ha desarrollado una solución para la versión 1.1.29. Se recomienda a los usuarios que actualicen. No se conocen workarounds para esta vulnerabilidad.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-10-30 CVE Reserved
- 2023-11-14 CVE Published
- 2024-08-14 CVE Updated
- 2024-11-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://owasp.org/www-community/vulnerabilities/PHP_Object_Injection | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/yiisoft/yii/commit/37142be4dc5831114a375392e86d6450d4951c06 | 2023-11-20 | |
https://github.com/yiisoft/yii/security/advisories/GHSA-mw2w-2hj2-fg8q | 2023-11-20 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Yiiframework Search vendor "Yiiframework" | Yii Search vendor "Yiiframework" for product "Yii" | < 1.1.29 Search vendor "Yiiframework" for product "Yii" and version " < 1.1.29" | - |
Affected
|