Zend Framework

Zend_Json internal does not encode solidus when encoding strings

Details

  • Type: Bug Bug
  • Status: Resolved Resolved
  • Priority: Major Major
  • Resolution: Fixed
  • Affects Version/s: 1.9.6
  • Fix Version/s: 1.7.9, 1.8.5, 1.9.7
  • Component/s: Zend_Json
  • Labels:
    None
  • Fix Version Priority:
    Must Have

Description

Zend_Json's internal encoder fails to encode the solidus (http://www.json.org/ and http://www.json.org/string.gif) when attempting to encode strings. This could potentially result a potential security risk when transfering un-escaped and unsafe HTML to a json client who's primary intention is to display it in the browser.

Activity

There are no comments yet on this issue.

People

Vote (0)
Watch (0)

Dates

  • Created:
    Updated:
    Resolved:

Time Tracking

Estimated:
1h
Original Estimate - 1 hour
Remaining:
1h
Remaining Estimate - 1 hour
Logged:
Not Specified
Time Spent - Not Specified