Back to Labs
Security Advisory

CVE-2023-26750

About

SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.

Weakness (CWE):CWE-89CWE-79

Rainforest analyst review

This is filed as a SQL injection in the Yii 2 framework before 2.0.47, reachable via the runAction function and rated critical unauthenticated, but the maintainer's stated position is important: they hold that the vulnerability lives in third-party code, not in the framework itself. That dispute means the 9.8 should be read as an upper bound that may not reflect a defect in Yii as shipped.

The nuance matters for exploitation reality. If the injectable path only manifests when application code uses runAction in a particular unsafe way, then the risk is concentrated in specific applications rather than being a blanket property of every Yii deployment, which is very different from a framework-wide unauthenticated hole. Blindly treating it as a universal critical would over-weight it.

Our recommendation is to rank it with the dispute front and center: rather than mass-patching on the CVSS, we would identify whether our Yii-based applications actually use the affected pattern with untrusted input. Where they do, fix and update; where they don't, note the maintainer's position and avoid burning cycles. This is a case for reading the code, not just the score.

References

Related CVEs

Frequently asked questions

What is CVE-2023-26750?

SQL injection vulnerability found in Yii Framework Yii 2 Framework before v.2.0.47 allows the a remote attacker to execute arbitrary code via the runAction function. NOTE: the software maintainer's position is that the vulnerability is in third-party code, not in the framework.

How severe is CVE-2023-26750?

CVE-2023-26750 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2023-26750 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2023-26750?

Public advisories list the following as affected: yii. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2023-26750?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email