MEDIUM6.1
GHSA-rh3c-7wqx-6w95
zend-diactoros Cross-site Scripting (XSS)
Quick fix
GHSA-rh3c-7wqx-6w95 — zendframework/zend-diactoros: upgrade to the fixed version with the command below.
composer require zendframework/zend-diactoros:^1.0.4Details
`Zend/Diactoros/Uri::filterPath` in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site scripting (XSS) or open redirect attacks.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/zendframework/zend-diactoros
Introduced in:
1.0.0Fixed in: 1.0.4Fix
composer require zendframework/zend-diactoros:^1.0.4References
- https://nvd.nist.gov/vuln/detail/CVE-2015-3257[ADVISORY]
- https://framework.zend.com/security/advisory/ZF2015-05[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-diactoros/CVE-2015-3257.yaml[WEB]
- https://github.com/zendframework/zend-diactoros[PACKAGE]
- http://www.securityfocus.com/bid/75466[WEB]