CVE-2018-6009 is a high-severity vulnerability affecting Yii Framework 2.x versions prior to 2.0.14. It stems from the switchIdentity function in web/User.php failing to regenerate the CSRF token when a user's identity changes, leading to a Cross-Site Request Forgery (CSRF) weakness (CWE-352). This vulnerability has a CVSS score of 8.8, indicating a high potential for impact on confidentiality, integrity, and availability, and can be exploited remotely with low attack complexity, requiring user interaction. Despite its severity, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:yiiframework:yiiframework:2.0.0:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:yiiframework:yiiframework:2.0.0:alpha:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:yiiframework:yiiframework:2.0.0:beta:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:yiiframework:yiiframework:2.0.0:rc:*:*:*:*:*:* | ||
2.0.1CPE matchmatch criteria | cpe:2.3:a:yiiframework:yiiframework:2.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.