VDB
Sign up
MEDIUM6.1

GHSA-j543-vg33-g6vj

ZendFramework potential Cross-site Scripting vector in `Zend_Dojo_View_Helper_Editor`

Quick fix

GHSA-j543-vg33-g6vj — zendframework/zendframework1: upgrade to the fixed version with the command below.

composer require zendframework/zendframework1:^1.7.9

Details

`Zend_Dojo_View_Helper_Editor` was incorrectly decorating a TEXTAREA instead of a DIV. The Dojo team has reported that this has security implications as the rich text editor they use is unable to escape content for a TEXTAREA.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zendframework/zendframework1
Introduced in: 1.7.0Fixed in: 1.7.9
Fixcomposer require zendframework/zendframework1:^1.7.9
Packagist/zendframework/zendframework1
Introduced in: 1.8.0Fixed in: 1.8.5
Fixcomposer require zendframework/zendframework1:^1.8.5
Packagist/zendframework/zendframework1
Introduced in: 1.9.0Fixed in: 1.9.7
Fixcomposer require zendframework/zendframework1:^1.9.7

References