GHSA-4xh9-5vh8-3p58
Dashboard / Vulnerabilities / GHSA-4xh9-5vh8-3p58
Summary: Yii Framework Reflected XSS
Details: Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-7271, https://github.com/yiisoft/yii2/pull/13401, https://github.com/yiisoft/yii2/commit/97171a0db7cda0a49931ee0c3b998ef50bd06756, https://github.com/yiisoft/yii2, https://web.archive.org/web/20210125191138/http://www.securityfocus.com/bid/97167, http://www.yiiframework.com/news/123/yii-2-0-11-is-released
Affected packages
Package
Name: yiisoft/yii2
Purl: pkg:composer/yiisoft/yii2
Affected ranges
Type: ECOSYSTEM
Events:
