Remote Code Injection Vulnerability in Yii Framework by Yii Software
CVE-2018-8074

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
21 March 2018

What is CVE-2018-8074?

The Yii Framework version 2.x, prior to 2.0.15, contains a vulnerability that allows remote attackers to inject unintended search conditions, presenting a serious threat when exploited in conjunction with the Elasticsearch extension. This vulnerability represents a variant of a previously identified attack vector, which could potentially enable attackers to manipulate data queries and perform unauthorized actions, compromising the integrity of applications built on the Yii Framework.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-8074 : Remote Code Injection Vulnerability in Yii Framework by Yii Software