Loading
Generated remediation guidance and an executive summary. No account required.
Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.
Use CWE-94, Yiiframework vendor hub and Gii product page to widen CVE-2020-36655 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-34297 for nearby disclosures in the same product family.