GHSA-5957-5crx-79jx
Dashboard / Vulnerabilities / GHSA-5957-5crx-79jx
Summary: Zenario CMS vulnerable to CRLF injection
Details: CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-3154, https://framework.zend.com/security/advisory/ZF2015-04, https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-http/CVE-2015-3154.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework/CVE-2015-3154.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework1/CVE-2015-3154.yaml, https://github.com/zendframework/zendframework
Affected packages
Package
Name: zendframework/zend-http
Purl: pkg:composer/zendframework/zend-http
Affected ranges
Type: ECOSYSTEM
Events:
