Cross-Site Scripting Vulnerability in Yii Framework by Yii Software
CVE-2015-3397

Currently unrated

Key Information:

Vendor
CVE Published:
14 May 2015

What is CVE-2015-3397?

A cross-site scripting vulnerability exists in the Yii Framework prior to version 2.0.4, allowing remote attackers to inject arbitrary web scripts or HTML. This can be exploited via specific vectors that involve JSON and arrays while targeting users on Internet Explorer versions 6 or 7. Successful exploitation may compromise user sessions and lead to unauthorized actions within a vulnerable application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2015-3397 : Cross-Site Scripting Vulnerability in Yii Framework by Yii Software