VYPR
High severity8.1NVD Advisory· Published Mar 21, 2018· Updated Jun 17, 2026

CVE-2018-8074

CVE-2018-8074

Description

Yii 2.x before 2.0.15 allows remote attackers to inject unintended search conditions via a variant of the CVE-2018-7269 attack in conjunction with the Elasticsearch extension.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
yiisoft/yii2-devPackagist
>= 2.0.0, < 2.0.152.0.15
yiisoft/yii2-elasticsearchPackagist
< 2.0.52.0.5

Affected products

2

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.