Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Yii does not prevent XSS in scenarios where fallback error renderer is used
Vulnerability Description
Yii is an open source PHP web framework. Prior to 1.1.31, yiisoft/yii is vulnerable to Reflected XSS in specific scenarios where the fallback error renderer is used. Upgrade yiisoft/yii to version 1.1.31 or higher.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Yii 安全漏洞
Vulnerability Description
Yii是YII团队的开发的一套基于组件、用于开发大型Web应用的高性能PHP框架。 Yii 1.1.31之前版本存在安全漏洞,该漏洞源于反射型跨站脚本。
CVSS Information
N/A
Vulnerability Type
N/A