{"api_version":"1","generated_at":"2026-07-23T03:38:00+00:00","cve":"CVE-2017-7271","urls":{"html":"https://cve.report/CVE-2017-7271","api":"https://cve.report/api/cve/CVE-2017-7271.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-7271","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-7271"},"summary":{"title":"CVE-2017-7271","description":"Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen.","state":"PUBLISHED","assigner":"mitre","published_at":"2017-03-27 17:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.yiiframework.com/news/123/yii-2-0-11-is-released/","name":"http://www.yiiframework.com/news/123/yii-2-0-11-is-released/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"],"title":"Yii 2.0.11 is released | News | Yii PHP Framework","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/97167","name":"http://www.securityfocus.com/bid/97167","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Yii framework CVE-2017-7271 Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/yiisoft/yii2/commit/97171a0db7cda0a49931ee0c3b998ef50bd06756","name":"https://github.com/yiisoft/yii2/commit/97171a0db7cda0a49931ee0c3b998ef50bd06756","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Fixes #13401: Fixed lack of escaping of request dump at exception scr… · yiisoft/yii2@97171a0 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/yiisoft/yii2/pull/13401","name":"https://github.com/yiisoft/yii2/pull/13401","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Fixes lack of escaping of request dump at exception screens by samdark · Pull Request #13401 · yiisoft/yii2 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-7271","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7271","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"7271","vulnerable":"1","versionEndIncluding":"2.0.10","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yii_software","cpe5":"yii","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T15:56:36.368Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.yiiframework.com/news/123/yii-2-0-11-is-released/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/yiisoft/yii2/commit/97171a0db7cda0a49931ee0c3b998ef50bd06756"},{"name":"97167","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/97167"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/yiisoft/yii2/pull/13401"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2017-03-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-05-07T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.yiiframework.com/news/123/yii-2-0-11-is-released/"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/yiisoft/yii2/commit/97171a0db7cda0a49931ee0c3b998ef50bd06756"},{"name":"97167","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/97167"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/yiisoft/yii2/pull/13401"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-7271","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.yiiframework.com/news/123/yii-2-0-11-is-released/","refsource":"CONFIRM","url":"http://www.yiiframework.com/news/123/yii-2-0-11-is-released/"},{"name":"https://github.com/yiisoft/yii2/commit/97171a0db7cda0a49931ee0c3b998ef50bd06756","refsource":"CONFIRM","url":"https://github.com/yiisoft/yii2/commit/97171a0db7cda0a49931ee0c3b998ef50bd06756"},{"name":"97167","refsource":"BID","url":"http://www.securityfocus.com/bid/97167"},{"name":"https://github.com/yiisoft/yii2/pull/13401","refsource":"CONFIRM","url":"https://github.com/yiisoft/yii2/pull/13401"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2017-7271","datePublished":"2017-03-27T17:00:00.000Z","dateReserved":"2017-03-27T00:00:00.000Z","dateUpdated":"2024-08-05T15:56:36.368Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-03-27 17:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:yii_software:yii:*:*:*:*:*:*:*:*","versionEndIncluding":"2.0.10","matchCriteriaId":"D5DCD2A8-1911-4C3E-B526-7913DA4BB3D8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"7271","Ordinal":"1","Title":"CVE-2017-7271","CVE":"CVE-2017-7271","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"7271","Ordinal":"1","NoteData":"Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen.","Type":"Description","Title":"CVE-2017-7271"},{"CveYear":"2017","CveId":"7271","Ordinal":"2","NoteData":"2017-03-27","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"7271","Ordinal":"3","NoteData":"2017-05-07","Type":"Other","Title":"Modified"}]}}}