In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| yiisoft/yii2(Packagist) | 2.0 | 2.0.14 | N/A |
| yiisoft/yii2-dev(Packagist) | 2.0 | 2.0.14 | N/A |
CVSS Metrics