Lucene search

K
cveMitreCVE-2020-36655
HistoryJan 21, 2023 - 1:15 a.m.

CVE-2020-36655

2023-01-2101:15:12
CWE-94
mitre
web.nvd.nist.gov
41
cve-2020-36655
yii
yii2
gii
remote code execution
security vulnerability

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.009

Percentile

82.8%

Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.

Affected configurations

Nvd
Node
yiiframeworkgiiRange<2.2.2yii2
VendorProductVersionCPE
yiiframeworkgii*cpe:2.3:a:yiiframework:gii:*:*:*:*:*:yii2:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.009

Percentile

82.8%

Related for CVE-2020-36655