CVE-2023-22727
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
CakePHP Database\\Query::offset() and limit() methods are vulnerable to SQL injection
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-22727
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bullseye | fixed | 0 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | cakephp/cakephp | >=4.2.0,<4.2.12 | 4.2.12 |
| Packagist | cakephp/cakephp | >=4.3.0,<4.3.11 | 4.3.11 |
| Packagist | cakephp/cakephp | >=4.4.0,<4.4.10 | 4.4.10 |
| Packagist | cakephp/database | >=4.2.0,<4.2.12 | 4.2.12 |
| Packagist | cakephp/database | >=4.3.0,<4.3.11 | 4.3.11 |
| Packagist | cakephp/database | >=4.4.0,<4.4.10 | 4.4.10 |
References
- https://security-tracker.debian.org/tracker/CVE-2023-22727
- https://github.com/cakephp/cakephp/security/advisories/GHSA-6g8q-qfpv-57wp
- https://nvd.nist.gov/vuln/detail/CVE-2023-22727
- https://github.com/cakephp/cakephp/commit/3f463e7084b5a15e67205ced3a622577cca7a239
- https://bakery.cakephp.org/2023/01/06/cakephp_4211_4311_4410_released.html
- https://github.com/cakephp/cakephp
Verify integrity in audit chain (admin only). AS-IS.