VDB
Sign up
CRITICAL9.8

GHSA-6g8q-qfpv-57wp

CakePHP Database\\Query::offset() and limit() methods are vulnerable to SQL injection

Quick fix

GHSA-6g8q-qfpv-57wp — cakephp/cakephp: upgrade to the fixed version with the command below.

composer require cakephp/cakephp:^4.2.12

Details

### Impact

The `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data.

### Patches This issue has been fixed in 4.2.12, 4.3.11, 4.4.10

### Workarounds

Using CakePHP's Pagination library will mitigate this issue, as will validating or casting parameters to these methods.

### References

https://bakery.cakephp.org/2023/01/06/cakephp_4211_4311_4410_released.html

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cakephp/cakephp
Introduced in: 4.2.0Fixed in: 4.2.12
Fixcomposer require cakephp/cakephp:^4.2.12
Packagist/cakephp/cakephp
Introduced in: 4.3.0Fixed in: 4.3.11
Fixcomposer require cakephp/cakephp:^4.3.11
Packagist/cakephp/cakephp
Introduced in: 4.4.0Fixed in: 4.4.10
Fixcomposer require cakephp/cakephp:^4.4.10
Packagist/cakephp/database
Introduced in: 4.2.0Fixed in: 4.2.12
Fixcomposer require cakephp/database:^4.2.12
Packagist/cakephp/database
Introduced in: 4.3.0Fixed in: 4.3.11
Fixcomposer require cakephp/database:^4.3.11
Packagist/cakephp/database
Introduced in: 4.4.0Fixed in: 4.4.10
Fixcomposer require cakephp/database:^4.4.10

References