Логотип exploitDog
bind:CVE-2023-22727
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-22727

Количество 3

Количество 3

ubuntu логотип

CVE-2023-22727

около 3 лет назад

CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP's Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-22727

около 3 лет назад

CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP's Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-6g8q-qfpv-57wp

около 3 лет назад

CakePHP Database\\Query::offset() and limit() methods are vulnerable to SQL injection

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-22727

CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP's Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-22727

CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP's Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue.

CVSS3: 9.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-6g8q-qfpv-57wp

CakePHP Database\\Query::offset() and limit() methods are vulnerable to SQL injection

CVSS3: 9.8
0%
Низкий
около 3 лет назад

Уязвимостей на страницу