Vulnerability Intelligence Report
Unsafe deserialization of user data in yiisoft/yii
CVE-2023-47130
Yii is an open source PHP web framework. yiisoft/yii before version 1.1.29 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. An attacker may leverage this vulnerability to compromise the host system. A fix has been developed for the 1.1.29 release. Users are advised to upgrade. There are no known workarounds for this vulnerability.
No Active Exploit Signals
CVSS Base Score
8.1
HIGH
Exploitability:2.3
Impact Score:5.9
EPSS Probability:3.15%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-502 ↗CWE-502: Deserialization of Untrusted Data
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| yiisoft | yii | < 1.1.29 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
3.147%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2023-10-30T19:57:51 |
| Published | 2023-11-14T20:30:16 |
| Last Updated | 2024-08-14T19:26:42 |
Community Chatter & Buzz