CVE-2024-58136

Published
View on NVD ↗
CVSS v3
9
CRITICAL
CVSS v2
N/A
Affected
1
PROJECT

Description

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

Yii 2: The Fast, Secure and Professional PHP Framework
GitHubGitHub
14.3K