CVE-2022-41922
23.11.2022, 18:15
`yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27.Enginsight
Vendor | Product | Version |
---|---|---|
yiiframework | yii | 𝑥 < 1.1.27 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References