CRITICAL9.8
GHSA-6g8q-qfpv-57wp
CakePHP Database\\Query::offset() and limit() methods are vulnerable to SQL injection
Quick fix
GHSA-6g8q-qfpv-57wp — cakephp/cakephp: upgrade to the fixed version with the command below.
composer require cakephp/cakephp:^4.2.12Details
### Impact
The `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` methods are vulnerable to SQL injection if passed un-sanitized user request data.
### Patches This issue has been fixed in 4.2.12, 4.3.11, 4.4.10
### Workarounds
Using CakePHP's Pagination library will mitigate this issue, as will validating or casting parameters to these methods.
### References
https://bakery.cakephp.org/2023/01/06/cakephp_4211_4311_4410_released.html
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/cakephp/cakephp
Introduced in:
4.2.0Fixed in: 4.2.12Fix
composer require cakephp/cakephp:^4.2.12Packagist/cakephp/cakephp
Introduced in:
4.3.0Fixed in: 4.3.11Fix
composer require cakephp/cakephp:^4.3.11Packagist/cakephp/cakephp
Introduced in:
4.4.0Fixed in: 4.4.10Fix
composer require cakephp/cakephp:^4.4.10Packagist/cakephp/database
Introduced in:
4.2.0Fixed in: 4.2.12Fix
composer require cakephp/database:^4.2.12Packagist/cakephp/database
Introduced in:
4.3.0Fixed in: 4.3.11Fix
composer require cakephp/database:^4.3.11Packagist/cakephp/database
Introduced in:
4.4.0Fixed in: 4.4.10Fix
composer require cakephp/database:^4.4.10References
- https://github.com/cakephp/cakephp/security/advisories/GHSA-6g8q-qfpv-57wp[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-22727[ADVISORY]
- https://github.com/cakephp/cakephp/commit/3f463e7084b5a15e67205ced3a622577cca7a239[WEB]
- https://bakery.cakephp.org/2023/01/06/cakephp_4211_4311_4410_released.html[WEB]
- https://github.com/cakephp/cakephp[PACKAGE]