CVE-2022-41922

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
23/11/2022
Last modified:
30/11/2022

Description

`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:* 1.1.27 (excluding)