CVE-2015-3154Injection in Framework

CWE-74Injection11 documents5 sources
Severity
6.1MEDIUMNVD
EPSS
0.3%
top 49.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 27
Latest updateMay 24

Description

CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the header of an email.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

Packagistzendframework/zend-http2.0.0beta42.3.8+2
NVDzend/zend_framework2.3.02.3.8+2
Packagistzendframework/zendframework2.0.0beta42.3.8+1
Packagistzendframework/zendframework1< 1.12.12
CVEListV5zend_technologies/zend_framework2.4.x before 2.4.1, 2.x before 2.3.8, before 1.12.12+2

🔴Vulnerability Details

4
OSV
Zenario CMS vulnerable to CRLF injection2022-05-24
GHSA
Zenario CMS vulnerable to CRLF injection2022-05-24
CVEList
CVE-2015-3154: CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 12020-01-27
OSV
CVE-2015-3154: CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 12020-01-27

💬Community

6
Bugzilla
CVE-2015-3154 php-ZendFramework: php-ZendFramework2: ZF2015-04: Potential header and mail injection vulnerability [epel-all]2015-05-21
Bugzilla
CVE-2015-3154 php-ZendFramework: php-ZendFramework2: ZF2015-04: Potential header and mail injection vulnerability [fedora-all]2015-05-21
Bugzilla
CVE-2015-3154 php-ZendFramework2: ZF2015-04: Potential header and mail injection vulnerability [fedora-all]2015-05-21
Bugzilla
CVE-2015-3154 php-ZendFramework2: ZF2015-04: Potential header and mail injection vulnerability [epel-all]2015-05-21
Bugzilla
CVE-2015-3154 php-ZendFramework: php-ZendFramework2: ZF2015-04: Potential header and mail injection vulnerability [fedora-all]2015-05-21
CVE-2015-3154 — Injection in Zend Framework | cvebase