Vulnerability Description
An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception->errorInfo is mishandled.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yiiframework | Yii | 2.0.12 |
Related Weaknesses (CWE)
References
- https://github.com/yiisoft/yii2/pull/14492Issue TrackingPatchThird Party Advisory
- https://github.com/yiisoft/yii2/pull/14492/files/feb4067de8a58f391a66e395192b0d8Issue TrackingPatchThird Party Advisory
- https://github.com/yiisoft/yii2/pull/14492Issue TrackingPatchThird Party Advisory
- https://github.com/yiisoft/yii2/pull/14492/files/feb4067de8a58f391a66e395192b0d8Issue TrackingPatchThird Party Advisory
FAQ
What is CVE-2017-11516?
CVE-2017-11516 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception->errorInfo is mishandled...
How severe is CVE-2017-11516?
CVE-2017-11516 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11516?
Check the references section above for vendor advisories and patch information. Affected products include: Yiiframework Yii.