CRLF Injection Vulnerability in Zend Framework Email Component
CVE-2015-3154
6.1MEDIUM
What is CVE-2015-3154?
The CRLF injection vulnerability in the Zend Framework's email component allows remote attackers to exploit weaknesses in the handling of HTTP headers. By injecting CRLF sequences into the email header, attackers can execute HTTP response splitting attacks, which may lead to the manipulation of the web application's responses. This presents a significant risk, as it can potentially compromise the integrity and confidentiality of the data transmitted. It is essential for users of affected Zend Framework versions to apply the appropriate security updates to mitigate this risk.
Affected Version(s)
Zend Framework before 1.12.12
Zend Framework 2.x before 2.3.8
Zend Framework 2.4.x before 2.4.1