ZeroHour

CVE-2018-6010

CVSS 3.0
7.5 high
EPSS
3%p86
Published
()
Modified
Description

In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit reflected XSS on the error handler page in non-debug mode. Related to base/ErrorHandler.php, log/Dispatcher.php, and views/errorHandler/exception.php.

Vendors
yiiframework
Products
yiiframework
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.