CVE-2023-26750

CVSS V2 None CVSS V3 None
Description
** DISPUTED ** SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.
Overview
  • CVE ID
  • CVE-2023-26750
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Modified
  • Published Version
  • 2023-04-04T15:15:08
  • Last Modified Date
  • 2023-04-14T20:15:09
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:* 1 OR 2.0.0 2.0.47
History
Created Old Value New Value Data Type Notes
2023-04-17 04:06:38 Added to TrackCVE
2023-04-17 04:06:41 Weakness Enumeration new