CVE-2020-36655
21.01.2023, 01:15
Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.
Vendor | Product | Version |
---|---|---|
yiiframework | gii | 𝑥 < 2.2.2 |
𝑥
= Vulnerable software versions