High severity8.1NVD Advisory· Published Mar 21, 2018· Updated Jun 17, 2026
CVE-2018-8074
CVE-2018-8074
Description
Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elasticsearch extension.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
yiisoft/yii2-devPackagist | >= 2.0.0, < 2.0.15 | 2.0.15 |
yiisoft/yii2-elasticsearchPackagist | < 2.0.5 | 2.0.5 |
Affected products
2- ghsa-coords2 versions
>= 2.0.0, < 2.0.15+ 1 more
- (no CPE)range: >= 2.0.0, < 2.0.15
- (no CPE)range: < 2.0.5
Patches
Vulnerability mechanics
References
6- www.yiiframework.com/news/168/releasing-yii-2-0-15-and-database-extensions-with-security-fixes/nvdVendor Advisory
- github.com/advisories/GHSA-m2p5-fwp2-qcw2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-8074ghsaADVISORY
- www.yiiframework.com/news/168/releasing-yii-2-0-15-and-database-extensions-with-security-fixesghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/yiisoft/yii2-elasticsearch/CVE-2018-8074.yamlghsaWEB
- www.yiiframework.com/news/168/releasing-yii-2-0-15-and-database-extensions-with-security-fixesghsaWEB
News mentions
0No linked articles in our index yet.