CVE-2024-58136

unknown KEV
Published 2025-04-10 · Modified 2025-05-02
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H
CVSS v2
VIR risk
1.5

Description

Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement Yii, including—but not limited to—Craft CMS, as represented by CVE-2025-32432.

CISA KEV

Vendor
Yiiframework
Product
Yii
Due date
2025-05-23

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52 ; https://nvd.nist.gov/vuln/detail/CVE-2024-58136

Exploits

Package impact

EcosystemPackageVulnerableFixed
php Packagistyiisoft/yii2<2.0.522.0.52

References

Verify integrity in audit chain (admin only). AS-IS.