VYPR
Medium severity6.1NVD Advisory· Published Jul 21, 2017· Updated May 13, 2026

CVE-2017-11516

CVE-2017-11516

Description

An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception->errorInfo is mishandled.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
yiisoft/yii2-devPackagist
>= 2.0.12, < 2.0.132.0.13
yiisoft/yii2Packagist
>= 2.0.12, < 2.0.132.0.13

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.