CVE-2025-2690

A vulnerability, which was classified as critical, was found in yiisoft Yii2 up to 2.0.39. This affects the function Generate of the file phpunit\src\Framework\MockObject\MockClass.php. The manipulation leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/gaorenyusi/gaorenyusi/blob/main/Yii2-2.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.300711 Permissions Required VDB Entry
https://vuldb.com/?id.300711 Permissions Required VDB Entry
https://vuldb.com/?submit.521718 VDB Entry Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:*

History

24 Mar 2025, 17:15

Type Values Removed Values Added
First Time Yiiframework yii
Yiiframework
CPE cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:*
References () https://github.com/gaorenyusi/gaorenyusi/blob/main/Yii2-2.md - () https://github.com/gaorenyusi/gaorenyusi/blob/main/Yii2-2.md - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.300711 - () https://vuldb.com/?ctiid.300711 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.300711 - () https://vuldb.com/?id.300711 - Permissions Required, VDB Entry
References () https://vuldb.com/?submit.521718 - () https://vuldb.com/?submit.521718 - VDB Entry, Third Party Advisory

24 Mar 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-24 08:15

Updated : 2025-03-24 17:15


NVD link : CVE-2025-2690

Mitre link : CVE-2025-2690

CVE.ORG link : CVE-2025-2690


JSON object : View

Products Affected

yiiframework

  • yii
CWE
CWE-20

Improper Input Validation

CWE-502

Deserialization of Untrusted Data