VDB
Sign up
MEDIUM6.1

GHSA-vvm3-rv48-j3g5

Zendframework Potential XSS or HTML Injection vector in Zend_Json

Quick fix

GHSA-vvm3-rv48-j3g5 — zendframework/zendframework1: upgrade to the fixed version with the command below.

composer require zendframework/zendframework1:^1.7.9

Details

`Zend_Json_Encoder` was not taking into account the solidus character (/) during encoding, leading to incompatibilities with the JSON specification, and opening the potential for XSS or HTML injection attacks when returning HTML within a JSON string.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zendframework/zendframework1
Introduced in: 1.7.0Fixed in: 1.7.9
Fixcomposer require zendframework/zendframework1:^1.7.9
Packagist/zendframework/zendframework1
Introduced in: 1.8.0Fixed in: 1.8.5
Fixcomposer require zendframework/zendframework1:^1.8.5
Packagist/zendframework/zendframework1
Introduced in: 1.9.0Fixed in: 1.9.7
Fixcomposer require zendframework/zendframework1:^1.9.7

References