CVE-2024-4990 is a critical vulnerability in the yiisoft/yii2 framework (version 2.0.48) where the base Component class's __set() method lacks validation, enabling attackers to instantiate arbitrary classes and invoke methods. This allows for severe impacts including arbitrary code execution, sensitive information disclosure, and unauthorized access. With a CVSS score of 9.1 (CRITICAL), it presents a high-impact, low-complexity attack vector. While no public exploits like Metasploit or ExploitDB are available, the vulnerability has garnered significant community discussion and media coverage, including reports of a Craft CMS zero-day exploit, indicating potential active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.48CPE matchmatch criteria | cpe:2.3:a:yiiframework:yii:2.0.48:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.