{"id":"GHSA-hx3m-959f-v849","aliases":[],"url":"https://o3.security/vulnerability/GHSA-hx3m-959f-v849","summary":"ZendFramework local file inclusion vector in `Zend_View::setScriptPath()` and `render()`","details":"Zend_View is a component that utilizes PHP as a templating language. To utilize it, you specify \"script paths\" that contain view scripts, and then `render()` view scripts by specifying subdirectories within those script paths; the output is then returned as a string value which may be cached or directly output.\n\n`Zend_View::setScriptPath()` in versions up to and including 1.7.4 include a potential Local File Inclusion vulnerability. If untrusted input is used to specify the script path and/or view script itself, a malicious attacker could potentially specify a system directory and thus render a system file.\n\nAs an example, if the user-supplied string `/etc/passwd` or a relative path that resolved to that file, was supplied to `Zend_View::render()`, that file would be rendered.","published":"2024-06-07T21:07:38Z","modified":"2024-06-07T21:07:38Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"zendframework/zendframework1","fixedVersion":"1.7.5"}],"fix":null,"references":[{"type":"WEB","url":"https://framework.zend.com/security/advisory/ZF2009-01"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework1/ZF2009-01.yaml"},{"type":"PACKAGE","url":"https://github.com/zendframework/zf1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-06-07T21:07:38Z"}}