VDB
Sign up
CRITICAL9.8

GHSA-p9hp-3gpv-52w3

Zend Framework Allows SQL Injection

Quick fix

GHSA-p9hp-3gpv-52w3 — zendframework/zendframework: upgrade to the fixed version with the command below.

composer require zendframework/zendframework:^1.12.19

Details

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern `[\w]*` in a regular expression.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zendframework/zendframework
Introduced in: 0Fixed in: 1.12.19
Fixcomposer require zendframework/zendframework:^1.12.19
Packagist/zendframework/zendframework1
Introduced in: 0Fixed in: 1.12.19
Fixcomposer require zendframework/zendframework1:^1.12.19

References