MEDIUM6.1
GHSA-4c64-w8fg-xcq2
Yii Cross-site Scripting Framework vulnerability
Quick fix
GHSA-4c64-w8fg-xcq2 — yiisoft/yii2-dev: upgrade to the fixed version with the command below.
composer require yiisoft/yii2-dev:^2.0.13Details
An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception->errorInfo is mishandled.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/yiisoft/yii2-dev
Introduced in:
2.0.12Fixed in: 2.0.13Fix
composer require yiisoft/yii2-dev:^2.0.13