MEDIUM6.1
GHSA-j543-vg33-g6vj
ZendFramework potential Cross-site Scripting vector in `Zend_Dojo_View_Helper_Editor`
Quick fix
GHSA-j543-vg33-g6vj — zendframework/zendframework1: upgrade to the fixed version with the command below.
composer require zendframework/zendframework1:^1.7.9Details
`Zend_Dojo_View_Helper_Editor` was incorrectly decorating a TEXTAREA instead of a DIV. The Dojo team has reported that this has security implications as the rich text editor they use is unable to escape content for a TEXTAREA.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/zendframework/zendframework1
Introduced in:
1.7.0Fixed in: 1.7.9Fix
composer require zendframework/zendframework1:^1.7.9Packagist/zendframework/zendframework1
Introduced in:
1.8.0Fixed in: 1.8.5Fix
composer require zendframework/zendframework1:^1.8.5Packagist/zendframework/zendframework1
Introduced in:
1.9.0Fixed in: 1.9.7Fix
composer require zendframework/zendframework1:^1.9.7