VYPR

Packagist (Composer) package

zendframework/zend-diactoros

pkg:composer/zendframework/zend-diactoros

Vulnerabilities (1)

  • CVE-2015-3257MedAug 25, 2017
    affected >= 1.0.0, < 1.0.4fixed 1.0.4

    Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site scripting (XSS) or open redirect attacks.