Remote Code Execution in Yii2 Framework by Yii Vendor
CVE-2015-5467
9.8CRITICAL
What is CVE-2015-5467?
The Yii2 framework prior to version 2.0.5 contains a vulnerability in the ViewAction component that allows attackers to execute arbitrary local .php files. By manipulating the view parameter with a relative path, unauthorized users could potentially exploit this flaw to gain control over the application, posing significant security risks. Developers using affected versions must upgrade to avoid potential exploitation.