{"id":"CVE-2017-11516","aliases":["GHSA-4c64-w8fg-xcq2"],"url":"https://o3.security/vulnerability/CVE-2017-11516","summary":"Yii Cross-site Scripting Framework vulnerability","details":"An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception->errorInfo is mishandled.","published":"2017-07-21T19:29:00.520Z","modified":"2026-08-07T14:48:47.853221Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"yiisoft/yii2-dev","fixedVersion":"2.0.13"},{"ecosystem":"Packagist","name":"yiisoft/yii2","fixedVersion":"2.0.13"}],"fix":{"url":"https://github.com/yiisoft/yii2/pull/14492","label":"yiisoft/yii2#14492"},"references":[{"type":"FIX","url":"https://github.com/yiisoft/yii2/pull/14492"},{"type":"FIX","url":"https://github.com/yiisoft/yii2/pull/14492/files/feb4067de8a58f391a66e395192b0d83a8109b95"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:48:47.853221Z"}}