8.8
CVSSv3

CVE-2020-36655

Published: 21/01/2023 Updated: 30/01/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Yii Yii2 Gii prior to 2.2.2 allows remote malicious users to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

yiiframework gii