Loading
Generated remediation guidance and an executive summary. No account required.
A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\finder\Iterator\SortableIterator.php. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Use CWE-20, Yiiframework vendor hub and Yii product page to widen CVE-2025-2689 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-58136, CVE-2015-5467 and CVE-2023-26750 for nearby disclosures in the same product family.