Loading
Generated remediation guidance and an executive summary. No account required.
Yii 2.x through 2.0.15.1 actively converts a wildcard CORS policy into reflecting an arbitrary Origin header value, which is incompatible with the CORS security design, and could lead to CORS misconfiguration security problems.
Use CWE-346, Yiiframework vendor hub and Yii product page to widen CVE-2018-20745 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-58136, CVE-2015-5467 and CVE-2023-26750 for nearby disclosures in the same product family.