← voltar
CVE-2023-22727

Database Query::offset() and limit() vulnerable to SQL injection in cakephp

CVSS 9.8 CRITICALEPSS 0.9%CWE-89
Vexday Risk Score
28Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 9.8EPSS 0.9%KEV nãoPoC Patch
Ciclo de vida
17 jan 2023Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
CakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data. This issue has been fixed in 4.2.12, 4.3.11, 4.4.10. Users are advised to upgrade. Users unable to upgrade may mitigate this issue by using CakePHP's Pagination library. Manually validating or casting parameters to these methods will also mitigate the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
cakephp · cakephp

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →