CVE-2012-4451
Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4)…
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- zend/zend framework · fedoraproject/fedora · redhat/enterprise linux
- Source
- secalert@redhat.com
References
- http://framework.zend.com/security/advisory/ZF2012-03Vendor Advisory
- http://seclists.org/oss-sec/2012/q3/571Mailing List, Patch, Third Party Advisory
- http://seclists.org/oss-sec/2012/q3/573Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/55636Third Party Advisory, VDB Entry
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=688946#10Mailing List, Third Party Advisory
- https://bugs.gentoo.org/show_bug.cgi?id=436210Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=860738Issue Tracking, Patch, Third Party Advisory
- https://github.com/zendframework/zf2/commit/27131ca9520bdf1d4c774c71459eba32f2b10733Patch, Third Party Advisory
- http://framework.zend.com/security/advisory/ZF2012-03Vendor Advisory
- http://seclists.org/oss-sec/2012/q3/571Mailing List, Patch, Third Party Advisory
- http://seclists.org/oss-sec/2012/q3/573Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/55636Third Party Advisory, VDB Entry
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=688946#10Mailing List, Third Party Advisory
- https://bugs.gentoo.org/show_bug.cgi?id=436210Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=860738Issue Tracking, Patch, Third Party Advisory
- https://github.com/zendframework/zf2/commit/27131ca9520bdf1d4c774c71459eba32f2b10733Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.