
We found results for “”
CVE-2018-6009
Good to know:

Date: January 22, 2018
In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.
Language: PHP
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Cross-Site Request Forgery (CSRF)
CWE-352Top Fix

Upgrade Version
Upgrade to version yiisoft/yii2-dev - dev-bizley-patch-2;yiisoft/yii2-dev - dev-link;yiisoft/yii2-dev - dev-cebe/fix-cookie-params;yiisoft/yii2-dev - 2.0.14;matricks/yii2-blitz - no_fix;minii/web - no_fix;gamantha/pao-project - dev-nirwan;phpsmile/yii2 - dev-remove-yii-autoloader;phpsmile/yii2 - dev-issue-12407;phpsmile/yii2 - 2.1.x-dev;phpsmile/yii2 - dev-composite-url-rule;phpsmile/yii2 - dev-fixes-14366-upgrade-php-72alpha;phpsmile/yii2 - 2.0.0-alpha;phpsmile/yii2 - dev-i18n-language-normalization;sheng/yiicms - dev-language;sheng/yiicms - v1.2.0;imdake/yii2 - 2.0.14;nbcx/yii2 - 2.0.14;nbcx/yii2 - dev-master;nanodesu88/yii2 - no_fix;riisoft/framework - 2.0.14;redooc/yii2-dev - dev-improve-exceptions;redooc/yii2-dev - dev-verb-filter;redooc/yii2-dev - dev-99999-rbac-add-index-on-userid;dlds/yii2-banking - 1.4;sweethousecr/house - no_fix;esoftslimited/yii2-blog - no_fix;toir427/yii2-hello - no_fix;pragmaticlinux/yii-basic - no_fix;shunt/click-statistics - no_fix;klikar3/rgraph - 1.0.0-alpha10;klikar3/rgraph - 1.0.0-alpha3;klikar3/rgraph - 1.0.0-alpha6;klikar3/rgraph - v0.0.0-alpha;cargic/edu - no_fix;czechcamus/yii2-app-basic - no_fix;yetiforce/yii2 - 2.0.14;leaps/framework - dev-bizley-patch-2;leaps/framework - 2.0.14;leaps/framework - dev-cebe/fix-cookie-params;leaps/framework - dev-irc;ly/message_queue - 1.0;newicon/neon - dev-develop;newicon/neon - v1.1.2;newicon/neon - dev-neilc-listObject-docblock;kangqf/kblog_with_yii2 - no_fix;peskovsb/reporbac - no_fix;ruvents/yii2 - 2.0.15;bright-tech/yii2-ace-admin-theme - v0.2;ush-webdev/framework-alpha - no_fix;seffeng/yii_admin - no_fix;phpsmile/psyii2 - no_fix;sol-hiqdev/bare-yii2 - no_fix;seffeng/yii_demo - no_fix;mevyen/yii2-swoole-async - no_fix;mevyen/yii2-swoole-async - 1.0.1;eold/yii2-apidoc-generator - no_fix;hieupham0206/cloudteam-metronic - no_fix;cszchen/flatui - no_fix;chlalbuquerque/yii2-kitdevelop - no_fix;dengyifang/blog_demo - no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |