9.8
CVSSv3

CVE-2018-7269

Published: 21/03/2018 Updated: 20/04/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x prior to 2.0.15 allows remote malicious users to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input.

Vulnerable Product Search on Vulmon Subscribe to Product

yiiframework yii

Github Repositories

php code audit for cms vulnerabilities / 代码审计,对一些大型cms漏洞的复现研究,更新源码和漏洞exp

PHP-code-audit php code audit for cms vulnerabilities 记录自己对一些cms漏洞的审计学习, 欢迎师傅们star支持下, 持续更新中。 seacms seacms v645,v654,v655 命令执行漏洞 wordpress wordpress v475 sprintf格式化字符串注入漏洞 phpcms phpcmsv960 sqli注入漏洞 phpcmsv960 文件上传漏洞 phpcmsv962 sqli注入漏洞