Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-22727

Опубликовано: 17 янв. 2023
Источник: debian
EPSS Низкий

Описание

CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP's Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cakephpremovedpackage
cakephpnot-affectedbullseyepackage

Примечания

  • https://github.com/cakephp/cakephp/security/advisories/GHSA-6g8q-qfpv-57wp

  • Introduced by: https://github.com/cakephp/cakephp/commit/7d4200c36742ed39abf9e1b88f6483b8d7a4af7f (3.0.0-dev1)

  • Fixed by: https://github.com/cakephp/cakephp/commit/3f463e7084b5a15e67205ced3a622577cca7a239 (4.4.10)

EPSS

Процентиль: 76%
0.0093
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 3 лет назад

CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP's Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue.

CVSS3: 9.8
nvd
около 3 лет назад

CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP's Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue.

CVSS3: 9.8
github
около 3 лет назад

CakePHP Database\\Query::offset() and limit() methods are vulnerable to SQL injection

EPSS

Процентиль: 76%
0.0093
Низкий