GHSA-hg35-vqp3-fv39
ZendFramework potential Cross-site Scripting vectors due to inconsistent encodings
Quick fix
GHSA-hg35-vqp3-fv39 — zendframework/zendframework1: upgrade to the fixed version with the command below.
composer require zendframework/zendframework1:^1.9.7Details
A number of classes, primarily within the `Zend_Form`, `Zend_Filter`, `Zend_Form`, `Zend_Log` and `Zend_View components`, contained character encoding inconsistencies whereby calls to the `htmlspecialchars()` and htmlentities() functions used undefined or hard coded charset parameters. In many of these cases developers were unable to set a character encoding of their choice. These inconsistencies could, in specific circumstances, allow certain multibyte representations of special HTML characters pass through unescaped leaving applications potentially vulnerable to cross-site scripting (XSS) exploits. Such exploits would only be possible if a developer used a non-typical character encoding (such as UTF-7), allowed users to define the character encoding, or served HTML documents without a valid character set defined.
Are you affected?
Enter the version of the package you're using.
Affected packages
1.9.0Fixed in: 1.9.7composer require zendframework/zendframework1:^1.9.7