← volver
CVE-2023-22727

Database Query::offset() and limit() vulnerable to SQL injection in cakephp

CVSS 9.8 CRITICALEPSS 0.9%CWE-89
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.8EPSS 0.9%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
17 ene 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP's Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
cakephp · cakephp

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →