High severity8.8NVD Advisory· Published Jan 21, 2023· Updated Jun 17, 2026
CVE-2020-36655
CVE-2020-36655
Description
Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
yiisoft/yii2-giiPackagist | < 2.2.2 | 2.2.2 |
Affected products
3- Yii/Yii2 Giidescription
Patches
Vulnerability mechanics
References
6- github.com/yiisoft/yii2-gii/issues/433nvdExploitIssue TrackingThird Party AdvisoryWEB
- lab.wallarm.com/yii2-gii-remote-code-execution/nvdExploitMitigationThird Party Advisory
- github.com/advisories/GHSA-3mpg-q26j-83j5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-36655ghsaADVISORY
- github.com/yiisoft/yii2-gii/commit/ed61e0d85f43e23f79d7c9d1b4e5e5c09a32ce4bghsaWEB
- lab.wallarm.com/yii2-gii-remote-code-executionghsaWEB
News mentions
0No linked articles in our index yet.