{"id":"GHSA-hx3m-959f-v849","summary":"ZendFramework local file inclusion vector in `Zend_View::setScriptPath()` and `render()`","details":"Zend_View is a component that utilizes PHP as a templating language. To utilize it, you specify \"script paths\" that contain view scripts, and then `render()` view scripts by specifying subdirectories within those script paths; the output is then returned as a string value which may be cached or directly output.\n\n`Zend_View::setScriptPath()` in versions up to and including 1.7.4 include a potential Local File Inclusion vulnerability. If untrusted input is used to specify the script path and/or view script itself, a malicious attacker could potentially specify a system directory and thus render a system file.\n\nAs an example, if the user-supplied string `/etc/passwd` or a relative path that resolved to that file, was supplied to `Zend_View::render()`, that file would be rendered.","modified":"2024-06-07T21:07:38Z","published":"2024-06-07T21:07:38Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-06-07T21:07:38Z"},"references":[{"type":"WEB","url":"https://framework.zend.com/security/advisory/ZF2009-01"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework1/ZF2009-01.yaml"},{"type":"PACKAGE","url":"https://github.com/zendframework/zf1"}],"affected":[{"package":{"name":"zendframework/zendframework1","ecosystem":"Packagist","purl":"pkg:composer/zendframework/zendframework1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.7.0"},{"fixed":"1.7.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-hx3m-959f-v849/GHSA-hx3m-959f-v849.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}