Description
The Yii2 Gii extension was found in the web application. Gii is a Web-based code generator for Yii2, which should be enabled only for the development environment with a strict white-list of allowed IP addresses
Remediation
Disable the Gii extension or restrict access to proper IP addresses only
References
Related Vulnerabilities
WordPress admin accessible without HTTP authentication
Unrestricted access to Haproxy Data Plane API
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-2101)
Opencart Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3763)
Oracle JRE Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-10356)