PT-2017-12064 · Yii · Yii Framework

Samdark

·

Published

2017-07-21

·

Updated

2022-05-17

·

CVE-2017-11516

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Yii Framework version 2.0.12
Description A security issue exists due to the mishandling of $exception->errorInfo in the exception screen when debug mode is enabled. This affects the framework/views/errorHandler/exception.php file.
Recommendations For Yii Framework version 2.0.12, consider disabling debug mode to minimize the risk of exploitation until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-11516
GHSA-4C64-W8FG-XCQ2

Affected Products

Yii Framework