Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m7hr-j867-3f34

Опубликовано: 07 июн. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

ZendFramework has potential Cross-site Scripting vector in multiple view helpers

Many Zend Framework 2 view helpers were using the escapeHtml() view helper in order to escape HTML attributes, instead of the more appropriate escapeHtmlAttr(). In situations where user data and/or JavaScript is used to seed attributes, this can lead to potential cross site scripting (XSS) attack vectors.

Vulnerable view helpers include:

  • All Zend\Form view helpers.
  • Most Zend\Navigation (aka Zend\View\Helper\Navigation\*) view helpers.
  • All "HTML Element" view helpers: htmlFlash(), htmlPage(), htmlQuickTime().
  • Zend\View\Helper\Gravatar

Пакеты

Наименование

zendframework/zend-view

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 2.2.7

2.2.7

Наименование

zendframework/zend-view

composer
Затронутые версииВерсия исправления

>= 2.3.0, < 2.3.1

2.3.1

6.1 Medium

CVSS3

Дефекты

CWE-79

6.1 Medium

CVSS3

Дефекты

CWE-79