Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

WeSecureApp Blog

Find out the technical based penetration testing, vulnerability management, cybersecurity blogs by wesecureapp. We cover entire issues on security.....