Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
The product does not sufficiently protect all possible paths that a user can take to access restricted functionality or resources.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Yii | Yiiframework | * | 2.0.52 (excluding) |