Executive brief
Yii Framework 2 mishandles the attaching of behavior defined by an __class array key, resulting in an improper protection of alternate path vulnerability. This flaw is a regression of CVE-2024-4990 and allows remote attackers to execute arbitrary code. The vulnerability also impacts downstream products such as Craft CMS.
Affected products
- Yiiframework Yii 2 before 2.0.52
- Pixel & Tonic Craft CMS
Timeline
- 2025-04-09: disclosed: NVD Published Date
- 2025-05-02: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-02: exploited: Exploitation in the wild began as early as February 2025
- 2025-04-28: patched: Yii 2.0.52 released to address the regression