Remote Code Execution Vulnerability in Yii Framework by Yii Software
CVE-2018-8073
9.8CRITICAL
What is CVE-2018-8073?
A vulnerability in the Yii Framework allows remote attackers to execute arbitrary LUA code by exploiting a weakness in the handling of certain requests. This issue arises in versions prior to 2.0.15 in conjunction with the Redis extension, which can be targeted using a variant of a similar attack, exposing applications to significant security risks. It is essential to upgrade to the latest version to mitigate this vulnerability.