Loading
Generated remediation guidance and an executive summary. No account required.
The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input.
Use CWE-89, Yiiframework vendor hub and Yii product page to widen CVE-2018-7269 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-58136, CVE-2015-5467 and CVE-2023-26750 for nearby disclosures in the same product family.