VDB
Sign up
MEDIUM6.1

GHSA-4c64-w8fg-xcq2

Yii Cross-site Scripting Framework vulnerability

Quick fix

GHSA-4c64-w8fg-xcq2 — yiisoft/yii2-dev: upgrade to the fixed version with the command below.

composer require yiisoft/yii2-dev:^2.0.13

Details

An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception->errorInfo is mishandled.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/yiisoft/yii2-dev
Introduced in: 2.0.12Fixed in: 2.0.13
Fixcomposer require yiisoft/yii2-dev:^2.0.13
Packagist/yiisoft/yii2
Introduced in: 2.0.12Fixed in: 2.0.13
Fixcomposer require yiisoft/yii2:^2.0.13

References