{"id":"GHSA-4c64-w8fg-xcq2","summary":"Yii Cross-site Scripting Framework vulnerability","details":"An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception-\u003eerrorInfo is mishandled.","aliases":["CVE-2017-11516"],"modified":"2024-04-24T18:57:22.032315Z","published":"2022-05-17T02:26:08Z","database_specific":{"github_reviewed_at":"2024-04-24T18:32:51Z","nvd_published_at":"2017-07-21T19:29:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-11516"},{"type":"WEB","url":"https://github.com/yiisoft/yii2/pull/14492"},{"type":"WEB","url":"https://github.com/yiisoft/yii2/pull/14492/files/feb4067de8a58f391a66e395192b0d83a8109b95"},{"type":"PACKAGE","url":"https://github.com/yiisoft/yii2-framework"}],"affected":[{"package":{"name":"yiisoft/yii2-dev","ecosystem":"Packagist","purl":"pkg:composer/yiisoft/yii2-dev"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.12"},{"fixed":"2.0.13"}]}],"versions":["2.0.12","2.0.12.1","2.0.12.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4c64-w8fg-xcq2/GHSA-4c64-w8fg-xcq2.json"}},{"package":{"name":"yiisoft/yii2","ecosystem":"Packagist","purl":"pkg:composer/yiisoft/yii2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.12"},{"fixed":"2.0.13"}]}],"versions":["2.0.12","2.0.12.1","2.0.12.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4c64-w8fg-xcq2/GHSA-4c64-w8fg-xcq2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}