{"id":"CVE-2018-6010","details":"In Yii Framework 2.x before 2.0.14, remote attackers could obtain potentially sensitive information from exception messages, or exploit reflected XSS on the error handler page in non-debug mode. Related to base/ErrorHandler.php, log/Dispatcher.php, and views/errorHandler/exception.php.","aliases":["GHSA-8gfq-c54m-3rf6"],"modified":"2026-05-17T11:55:16.966467183Z","published":"2018-01-22T22:29:00.270Z","database_specific":{"unresolved_ranges":[{"vendor_product":"yiiframework:yiiframework","cpes":["cpe:2.3:a:yiiframework:yiiframework:2.0.0:*:*:*:*:*:*:*"],"extracted_events":[{"last_affected":"2.0.0"}],"source":"CPE_FIELD"}]},"references":[{"type":"REPORT","url":"https://github.com/yiisoft/yii2/issues/14711"},{"type":"REPORT","url":"https://github.com/yiisoft/yii2/pull/15534"},{"type":"FIX","url":"https://github.com/yiisoft/yii2/commit/6b0be47e0fa9c532e03b07b4369050582fcf5c7a"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}