Reflected cross-site scripting (XSS) In zendframework/zendframework1
Description
ZendFramework potential Cross-site Scripting vector in Zend_Dojo_View_Helper_Editor
Zend_Dojo_View_Helper_Editor was incorrectly decorating a TEXTAREA instead of a DIV. The Dojo team has reported that this has security implications as the rich text editor they use is unable to escape content for a TEXTAREA.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 1.7.9, 1.8.5, 1.9.7 |
Aliases
1.
References
1. 2.