CVE-2018-6010
—CVSS 3.0
7.5 high
EPSS
3%p86
Published
()
Modified
Description
In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit reflected XSS on the error handler page in non-debug mode. Related to base/ErrorHandler.php, log/Dispatcher.php, and views/errorHandler/exception.php.
- Vendors
- yiiframework
- Products
- yiiframework
- Weakness
- CWE-79
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.