Cross-Site Scripting Vulnerability in Yii 2 by Yii Software
CVE-2022-31454
6.1MEDIUM
What is CVE-2022-31454?
Yii 2 version 2.0.45 contains a potential cross-site scripting (XSS) vulnerability discovered at the /books endpoint. This vulnerability could allow attackers to inject malicious scripts into web pages viewed by users, potentially compromising user data and overall web application security. However, the vendor has disputed the findings, suggesting that the relationship between the /books endpoint and Yii 2's security concerns is unclear. Developers utilizing Yii 2 are advised to follow best practices in web security and remain vigilant against potential exploitation.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved