VDB
Sign up
MEDIUM6.1

GHSA-hg35-vqp3-fv39

ZendFramework potential Cross-site Scripting vectors due to inconsistent encodings

Quick fix

GHSA-hg35-vqp3-fv39 — zendframework/zendframework1: upgrade to the fixed version with the command below.

composer require zendframework/zendframework1:^1.9.7

Details

A number of classes, primarily within the `Zend_Form`, `Zend_Filter`, `Zend_Form`, `Zend_Log` and `Zend_View components`, contained character encoding inconsistencies whereby calls to the `htmlspecialchars()` and htmlentities() functions used undefined or hard coded charset parameters. In many of these cases developers were unable to set a character encoding of their choice. These inconsistencies could, in specific circumstances, allow certain multibyte representations of special HTML characters pass through unescaped leaving applications potentially vulnerable to cross-site scripting (XSS) exploits. Such exploits would only be possible if a developer used a non-typical character encoding (such as UTF-7), allowed users to define the character encoding, or served HTML documents without a valid character set defined.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zendframework/zendframework1
Introduced in: 1.9.0Fixed in: 1.9.7
Fixcomposer require zendframework/zendframework1:^1.9.7

References