In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade zendframework/zendframework1
to version 1.9.7, 1.8.5, 1.7.9 or higher.
Affected versions of zendframework/zendframework1
are vulnerable to HTML Injection.
Zend_Json_Encoder
was not taking into account the solidus character (/
) during encoding, leading to incompatibilities with the JSON specification, and opening the potential for XSS or HTML injection attacks when returning HTML within a JSON string.