VDB
Sign up
MEDIUM6.1

GHSA-rh3c-7wqx-6w95

zend-diactoros Cross-site Scripting (XSS)

Quick fix

GHSA-rh3c-7wqx-6w95 — zendframework/zend-diactoros: upgrade to the fixed version with the command below.

composer require zendframework/zend-diactoros:^1.0.4

Details

`Zend/Diactoros/Uri::filterPath` in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site scripting (XSS) or open redirect attacks.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zendframework/zend-diactoros
Introduced in: 1.0.0Fixed in: 1.0.4
Fixcomposer require zendframework/zend-diactoros:^1.0.4

References