An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception->errorInfo is mishandled.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| yiisoft/yii2-dev(Packagist) | 2.0.12 | 2.0.13 | N/A |
| yiisoft/yii2(Packagist) | 2.0.12 | 2.0.13 | N/A |
CVSS Metrics