GHSA-jq4p-mq33-w375
MODERATECVE-2022-23598When rendering validation error messages via the formElementErrors() view helper shipped with laminas-form, many messages will contain the submitted value. However, in vulnerable versions of laminas-form, the value was not being escaped for HTML contexts, which can potentially lead to a Reflected Cross-Site Scripting (XSS) attack.
- Affected
- < 2.17.1, >= 3.1.0, < 3.1.1, >= 3.0.0, < 3.0.2
- Fixed in
- 2.17.1
- Weakness
- CWE-79
- Published
- 2022-01-28
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference