Loading
Generated remediation guidance and an executive summary. No account required.
Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NOTE: this is disputed by the vendor because the cve-2022-31454-8e8555c31fd3 page does not describe why /books has a relationship to Yii 2.
Use CWE-79, Yiiframework vendor hub and Yii product page to widen CVE-2022-31454 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-58136, CVE-2015-5467 and CVE-2023-26750 for nearby disclosures in the same product family.