CVE-2024-4990

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 20, 2025
Updated: Apr 1, 2025

Summary

CVE-2024-4990 is a vulnerability affecting the yiisoft/yii2 version 2.0.48. The base Component class contains a weakness that fails to validate the value passed to the `__set()` magic method, allowing an attacker to instantiate unauthorized Behavior classes with given parameters during construction. This can potentially lead to critical consequences, such as execution of arbitrary code, sensitive data exposure, and unauthorized access, depending on the installed dependencies.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share