github.comexploit
https://github.com/gaorenyusi/gaorenyusi/blob/main/Yii2-2.md CVE-2025-2690
MEDIUM
yiisoft Yii2 MockClass.php generate deserialization
Record summary
CVE-2025-2690 has a selected CVSS score of 5.3 (medium).
Description
A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src\Framework\MockObject\MockClass.php. The manipulation leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 24, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 2.0.0 | affected | |
| 2.0.1 | affected | ||
| 2.0.2 | affected | ||
| 2.0.3 | affected | ||
| 2.0.4 | affected | ||
| 2.0.5 | affected | ||
| 2.0.6 | affected | ||
| 2.0.7 | affected | ||
| 2.0.8 | affected | ||
| 2.0.9 | affected | ||
| 2.0.10 | affected | ||
| 2.0.11 | affected | ||
| Showing 12 of 40 version ranges | |||
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-2690 VDB-300711 | CTI Indicators (IOB, IOC, IOA)signaturepermissions required
https://vuldb.com/?ctiid.300711 VDB-300711 | yiisoft Yii2 MockClass.php generate deserializationvdb entryTechnical description
https://vuldb.com/?id.300711 Submit #521718 | Yii Software LLC Yii 2.0 <=2.0.39 DeserializationThird-party advisory
https://vuldb.com/?submit.521718