GHSA-33rh-5hvf-5jjp
Dashboard / Vulnerabilities / GHSA-33rh-5hvf-5jjp
Summary: ZF-Commons ZfcUser Vulnerable to XSS in Login Redirect
Details: Cross-site scripting (XSS) vulnerability in `user/login.phtml` in ZF-Commons ZfcUser before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-1039, https://github.com/ZF-Commons/ZfcUser/issues/550, https://github.com/ZF-Commons/ZfcUser/commit/baf0e460, https://github.com/FriendsOfPHP/security-advisories/blob/master/zf-commons/zfc-user/CVE-2015-1039.yaml, https://github.com/ZF-Commons/ZfcUser, https://web.archive.org/web/20150202091028/http://www.securityfocus.com/bid/71931, http://www.openwall.com/lists/oss-security/2015/01/11/4
Affected packages
Package
Name: zf-commons/zfc-user
Purl: pkg:composer/zf-commons/zfc-user
Affected ranges
Type: ECOSYSTEM
Events:
