cbcvebase.
CVE-2022-23598
published 2022-01-28

CVE-2022-23598: laminas-form is a package for validating and displaying simple and complex forms. When rendering validation error messages via the `formElementErrors()` view…

PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.99%
59.1th percentile
laminas-form is a package for validating and displaying simple and complex forms. When rendering validation error messages via the `formElementErrors()` view helper shipped with laminas-form, many messages will contain the submitted value. However, in laminas-form prior to version 3.1.1, the value was not being escaped for HTML contexts, which could potentially lead to a reflected cross-site scripting attack. Versions 3.1.1 and above contain a patch to mitigate the vulnerability. A workaround is available. One may manually place code at the top of a view script where one calls the `formElementErrors()` view helper. More information about this workaround is available on the GitHub Security Advisory.

Affected

9 ranges
VendorProductVersion rangeFixed in
fedoraprojectfedora
fedoraprojectfedora
getlaminaslaminas-form< 2.17.12.17.1
getlaminaslaminas-form
getlaminaslaminas-form>= 3.0.0 < 3.0.23.0.2
laminaslaminas-form< 3.1.13.1.1
laminaslaminas-form>= 0 < 2.17.12.17.1
laminaslaminas-form>= 3.0.0 < 3.0.23.0.2
laminaslaminas-form>= 3.1.0 < 3.1.13.1.1

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.