Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Yii 安全漏洞
Vulnerability Description
Yii是Yii团队开发的一套基于组件、用于开发大型Web应用的高性能PHP框架。 Yii 2.x版本至2.0.15.1版本中存在安全漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
CVSS Information
N/A
Vulnerability Type
N/A