-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| zendframework/zend-view | composer | >= 2.0.0, < 2.2.7 | 2.2.7 |
| zendframework/zend-view | composer | >= 2.3.0, < 2.3.1 | 2.3.1 |
The vulnerability stems from using HTML body escaping (escapeHtml) instead of attribute-specific escaping (escapeHtmlAttr). Commit diffs show: