VYPR
Medium severity6.1NVD Advisory· Published Jan 28, 2022· Updated Jun 17, 2026

CVE-2022-23598

CVE-2022-23598

Description

laminas-form is a package for validating and displaying simple and complex forms. When rendering validation error messages via the formElementErrors() view helper shipped with laminas-form, many messages will contain the submitted value. However, in laminas-form prior to version 3.1.1, the value was not being escaped for HTML contexts, which could potentially lead to a reflected cross-site scripting attack. Versions 3.1.1 and above contain a patch to mitigate the vulnerability. A workaround is available. One may manually place code at the top of a view script where one calls the formElementErrors() view helper. More information about this workaround is available on the GitHub Security Advisory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
laminas/laminas-formPackagist
>= 3.1.0, < 3.1.13.1.1
laminas/laminas-formPackagist
>= 3.0.0, < 3.0.23.0.2
laminas/laminas-formPackagist
< 2.17.12.17.1

Affected products

2

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.