Lack of data validation In zendframework/zendframework
Description
Zenario CMS vulnerable to CRLF injection CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 2.3.8, 2.4.1 | ||
packagist | 2.3.8, 2.4.1, 1.12.12 | ||
packagist | 1.12.12 | ||
packagist | 1.12.12, 2.3.8, 2.4.1 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5.