Yii Yii2 Gii before 2.2.2 allows... CVE-2020-36655

- AV AC AU C I A
发布: 2023-01-21
修订: 2024-11-21

Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息