Описание
zend-diactoros Cross-site Scripting (XSS)
Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site scripting (XSS) or open redirect attacks.
Пакеты
Наименование
zendframework/zend-diactoros
composer
Затронутые версииВерсия исправления
>= 1.0.0, < 1.0.4
1.0.4
Связанные уязвимости
CVSS3: 6.1
nvd
больше 8 лет назад
Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site scripting (XSS) or open redirect attacks.