vendor:
Zend Framework
by:
Unknown
N/A
CVSS
N/A
Cross-Site Scripting (XSS), HTML Injection, Security Bypass
Unknown
CWE
Product Name: Zend Framework
Affected Version From: Prior to Zend Framework 1.7.9, 1.8.5, and 1.9.7
Affected Version To: Unknown
Patch Exists: YES
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
Input-validation vulnerabilities and weakness in Zend Framework
Attackers can exploit cross-site scripting and HTML-injection issues to execute arbitrary script code in the browser of an unsuspecting user. This can lead to the theft of authentication credentials and other attacks. Additionally, the security-bypass weakness can be leveraged to bypass certain security restrictions.
Mitigation:
Upgrade to Zend Framework versions 1.7.9, 1.8.5, or 1.9.7 or later.