GHSA-4xh9-5vh8-3p58

Suggest an improvement
Source
https://github.com/advisories/GHSA-4xh9-5vh8-3p58
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4xh9-5vh8-3p58/GHSA-4xh9-5vh8-3p58.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4xh9-5vh8-3p58
Aliases
Published
2022-05-17T02:46:54Z
Modified
2024-02-16T08:20:48.136383Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Yii Framework Reflected XSS
Details

Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen.

Database specific
{
    "nvd_published_at": "2017-03-27T17:59:00Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-07-27T21:12:39Z"
}
References

Affected packages

Packagist / yiisoft/yii2

Package

Name
yiisoft/yii2
Purl
pkg:composer/yiisoft/yii2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.11

Affected versions

2.*

2.0.0-alpha
2.0.0-beta
2.0.0-rc
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.0.10