CyberICT

CVE-2024-58136

Yiiframework · Published April 10, 2025

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

Affected Products

  • YII < 2.0.52

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H