Vulnerability DatabaseGHSA-mg7h-9qfx-4r83

GHSA-mg7h-9qfx-4r83
PHP vulnerability analysis and mitigation

Overview

Zend Framework versions 2.0.0 to 2.0.5 contain potential proxy injection vulnerabilities in multiple components (GHSA-mg7h-9qfx-4r83). The vulnerability affects Zend\Session\Validator\RemoteAddr and Zend\View\Helper\ServerUrl components, which were found to be improperly parsing HTTP headers for proxy information. This security issue was discovered and disclosed on November 29, 2012 (Zend Advisory).

Technical details

The vulnerability stems from two main components: In Zend\Session\Validator\RemoteAddr, if the client is behind a proxy server, the detection of the proxy URL was incorrect and could lead to invalid results on subsequent lookups. In Zend\View\Helper\ServerUrl, the helper would always generate a URL based on the proxy host when the server was behind a proxy, regardless of whether this was desired, and it did not account for proxy port or protocol information. The vulnerability has a CVSS v3.1 score of 5.9 (Moderate) with vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N (GitHub Advisory).

Impact

The vulnerability could potentially allow an attacker to spoof a proxied IP or host name. This could lead to bypass of IP-based security controls and potentially result in unauthorized access to protected resources (Zend Advisory).

Exploitability

The vulnerability requires network access and has high attack complexity. No privileges are required to exploit the vulnerability, and no user interaction is needed. The vulnerability affects the integrity of the system but does not impact confidentiality or availability (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in Zend Framework version 2.0.5. The fix included the development of a new class, Zend\Http\PhpEnvironment\RemoteAddress, for handling client IP detection via proxy headers. The patch removed support for the non-standard Client-IP header, added the ability to specify which header to check for proxy detection, and implemented support for trusted proxy server lists. For the ServerUrl helper, proxy detection was disabled by default, and support for detecting proxy port and protocol was added (Zend Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44741HIGH8.8
  • PHP logoPHP
  • pimcore/admin-ui-classic-bundle
NoYesAug 12, 2026
CVE-2026-47233MEDIUM6.5
  • PHP logoPHP
  • admidio/admidio
NoYesAug 12, 2026
CVE-2026-47132MEDIUM5.4
  • PHP logoPHP
  • thorsten/phpmyfaq
NoYesAug 12, 2026
CVE-2026-47234MEDIUM4.4
  • PHP logoPHP
  • admidio/admidio
NoYesAug 12, 2026
CVE-2026-49262LOW3
  • PHP logoPHP
  • aimeos/pagible
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management