VDB
Sign up
MEDIUM6.1

GHSA-4v57-pwvf-x35j

Zendframework potential Cross-site Scripting vector in `Zend_Service_ReCaptcha_MailHide`

Quick fix

GHSA-4v57-pwvf-x35j — zendframework/zendframework1: upgrade to the fixed version with the command below.

composer require zendframework/zendframework1:^1.7.9

Details

`Zend_Service_ReCaptcha_MailHide` had a potential XSS vulnerability. Due to the fact that the email address was never validated, and because its use of `htmlentities()` did not include the encoding argument, it was potentially possible for a malicious user aware of the issue to inject a specially crafted multibyte string as an attack via the CAPTCHA's email argument

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zendframework/zendframework1
Introduced in: 1.7.0Fixed in: 1.7.9
Fixcomposer require zendframework/zendframework1:^1.7.9
Packagist/zendframework/zendframework1
Introduced in: 1.8.0Fixed in: 1.8.5
Fixcomposer require zendframework/zendframework1:^1.8.5
Packagist/zendframework/zendframework1
Introduced in: 1.9.0Fixed in: 1.9.7
Fixcomposer require zendframework/zendframework1:^1.9.7

References