Yii does not prevent XSS in scenarios where fallback error renderer is used
Description
Published by the National Vulnerability Database
Apr 10, 2025
Published to the GitHub Advisory Database
Apr 11, 2025
Reviewed
Apr 11, 2025
Last updated
Apr 11, 2025
Impact
Affected versions of yiisoft/yii are vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used.
Patches
Upgrade yiisoft/yii to version 1.1.31 or higher.
References
If you have any questions or comments about this advisory, contact us through security form.
References