The findByCondition function in framework/db/ActiveRecord.php in Yii 2.x before 2.0.15 allows remote attackers to conduct SQL injection attacks via a findOne() or findAll() call, unless a developer recognizes an undocumented need to sanitize array input.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| yiisoft/yii2-dev(Packagist) | 0 | 2.0.12.1 | N/A |
| yiisoft/yii2-dev(Packagist) | 2.0.13 | 2.0.13.2 | N/A |
| yiisoft/yii2-dev(Packagist) | 2.0.14 | 2.0.15 | N/A |
CVSS Metrics