CVE-2020-15148 is a critical remote code execution vulnerability affecting the Yii 2 framework prior to version 2.0.38, caused by the unsafe deserialization of untrusted user input. With a maximum CVSS score of 10.0, this flaw allows unauthenticated remote attackers to execute arbitrary commands with low complexity, potentially leading to a total compromise of the host system. While there are no reported Metasploit modules or CISA KEV listings, the availability of Nuclei scanning templates and a high EPSS score of 0.93 indicate a significant risk of automated exploitation, necessitating an immediate upgrade to the fixed version.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.38CPE matchmatch criteria | cpe:2.3:a:yiiframework:yii:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.