menu
techminis

A naukri.com initiative

google-web-stories
source image

Securityaffairs

1w

read

387

img
dot

Image Credit: Securityaffairs

U.S. CISA adds Yii Framework and Commvault Command Center flaws to its Known Exploited Vulnerabilities catalog

  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Yii Framework and Commvault Command Center flaws to its Known Exploited Vulnerabilities catalog.
  • Commvault Command Center Path Traversal Vulnerability (CVE-2025-34028) and Yiiframework Yii Improper Protection of Alternate Path Vulnerability (CVE-2024-58136) were among the vulnerabilities added.
  • Threat actors exploited Craft CMS vulnerabilities, including an RCE in Craft CMS and an input validation flaw in the Yii framework, to upload a PHP file manager and compromise servers.
  • CISA orders federal agencies to fix the vulnerabilities by May 23, 2025, following the Binding Operational Directive 22-01 to address Known Exploited Vulnerabilities.

Read Full Article

like

23 Likes

For uninterrupted reading, download the app