{"id":"CVE-2023-47130","aliases":["GHSA-mw2w-2hj2-fg8q"],"url":"https://o3.security/vulnerability/CVE-2023-47130","summary":"Unsafe deserialization of user data in yiisoft/yii","details":"### Impact\nAffected versions of `yiisoft/yii` are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input.\n\n### Patches\nUpgrade `yiisoft/yii` to version 1.1.29 or higher.\n\n### For more information\nSee the following links for more details:\n- [Git commit](https://github.com/yiisoft/yii/commit/37142be4dc5831114a375392e86d6450d4951c06)\n- https://owasp.org/www-community/vulnerabilities/PHP_Object_Injection\n\nIf you have any questions or comments about this advisory, [contact us through security form](https://www.yiiframework.com/security).","published":"2023-11-14T20:30:16.393Z","modified":"2026-08-12T03:51:46.882115354Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"yiisoft/yii","fixedVersion":"1.1.29"}],"fix":{"url":"https://github.com/yiisoft/yii/commit/37142be4dc5831114a375392e86d6450d4951c06","label":"yiisoft/yii@37142be"},"references":[{"type":"WEB","url":"https://owasp.org/www-community/vulnerabilities/PHP_Object_Injection"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/47xxx/CVE-2023-47130.json"},{"type":"ADVISORY","url":"https://github.com/yiisoft/yii/security/advisories/GHSA-mw2w-2hj2-fg8q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-47130"},{"type":"FIX","url":"https://github.com/yiisoft/yii/commit/37142be4dc5831114a375392e86d6450d4951c06"},{"type":"PACKAGE","url":"https://github.com/yiisoft/yii"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:46.882115354Z"}}