MEDIUM6.1
GHSA-vvm3-rv48-j3g5
Zendframework Potential XSS or HTML Injection vector in Zend_Json
Quick fix
GHSA-vvm3-rv48-j3g5 — zendframework/zendframework1: upgrade to the fixed version with the command below.
composer require zendframework/zendframework1:^1.7.9Details
`Zend_Json_Encoder` was not taking into account the solidus character (/) during encoding, leading to incompatibilities with the JSON specification, and opening the potential for XSS or HTML injection attacks when returning HTML within a JSON string.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/zendframework/zendframework1
Introduced in:
1.7.0Fixed in: 1.7.9Fix
composer require zendframework/zendframework1:^1.7.9Packagist/zendframework/zendframework1
Introduced in:
1.8.0Fixed in: 1.8.5Fix
composer require zendframework/zendframework1:^1.8.5Packagist/zendframework/zendframework1
Introduced in:
1.9.0Fixed in: 1.9.7Fix
composer require zendframework/zendframework1:^1.9.7