漏洞描述 Yii是Yii团队的Yii是Yii团队开发的一套基于组件、用于开发大型Web应用的高性能PHP框架。 Yii Framework 2.0.14之前的2.x版本中存在跨站请求伪造漏洞,该漏洞源于在用户身份更换之后,web/User.php文件的‘switchIdentity’函数没有重新产生跨站请求伪造令牌。攻击者可利用该漏洞执行未授权的操作。
相关漏洞推荐 Astro Web Framework Cloudflare /_image 服务器端请求伪造漏洞(CVE-2025-58179) Spring Framework路径遍历漏洞(CVE-2024-38819) Vmware Spring Framework 逻辑缺陷漏洞 OpenOrange Business Framework访问控制错误漏洞(CVE-2024-42048) POC CVE-2020-0646: Microsoft .NET Framework - Remote Code Execution POC spring4shell-CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+ POC CVE-2016-6601: ZOHO WebNMS Framework <5.2 SP1 - Local File Inclusion POC CVE-2017-1000163: Phoenix Framework - Open Redirect POC CVE-2018-1271: Spring MVC Framework - Local File Inclusion POC CVE-2020-15148: Yii 2 < 2.0.38 - Remote Code Execution POC CVE-2020-15227: Nette Framework - Remote Code Execution POC CVE-2020-15920: Mida eFramework <=2.9.0 - Remote Command Execution POC CVE-2020-36708: WordPress Epsilon Framework Themes <=2.4.8 - Remote Code Execution