Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2471 | Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen. |
Github GHSA |
GHSA-4xh9-5vh8-3p58 | Yii Framework Reflected XSS |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T15:56:36.368Z
Reserved: 2017-03-27T00:00:00
Link: CVE-2017-7271
No data.
Status : Deferred
Published: 2017-03-27T17:59:00.947
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-7271
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA