Record summary

CVE-2020-15148 has a selected CVSS score of 8.9 (high); EIP currently links 2 repository PoCs and 1 Nuclei template.

Description

Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. This is fixed in version 2.0.38. A possible workaround without upgrading is available in the linked advisory.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
2
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List< 2.0.38affected
GitHub AdvisoryBefore 2.0.38 · Fixed in 2.0.38affected

Proofs of concept

2

Repository PoCs

GitHubMaskhe/CVE-2020-15148-bypassesRepository PoCby MaskheStars: 74Not analyzed1 file

4.4 KiB

GitHub

PoC details
GitHub0xkami/cve-2020-15148Repository PoCby 0xkamiStars: 6Not analyzed4 files

3.3 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALYii 2 < 2.0.38 - Remote Code ExecutionCVSS 10

Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.

Remediation

Upgrade to version 2.0.38 or later. A possible workaround without upgrading is available in the linked advisory.

WeaknessesCWE-502
Authorspikpikcu
Template tagscvecve2020rceyiiyiiframeworkvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CPE: cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5