{"id":"GHSA-p76f-wr22-4rv6","aliases":[],"url":"https://o3.security/vulnerability/GHSA-p76f-wr22-4rv6","summary":"CakePHP vulnerable to Remote File Inclusion through View template name manipulation","details":"CakePHP 2.x prior to 2.0.99, 2.1.99, 2.2.99, 2.3.99, 2.4.99, 2.5.99, 2.6.12, and 2.7.6 and 3.x prior to 3.0.15 and 3.1.4 is vulnerable to Remote File Inclusion through View template name manipulation.","published":"2023-01-20T23:35:01Z","modified":"2024-11-29T05:41:07.154891Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.0.99"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.1.99"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.2.99"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.3.99"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.4.99"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.5.99"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.6.12"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"2.7.6"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"3.0.15"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"3.1.4"}],"fix":{"url":"https://github.com/cakephp/cakephp/commit/5e60cc5d182e6131e3fbdfdf69f49d560c9ff78b","label":"cakephp/cakephp@5e60cc5"},"references":[{"type":"WEB","url":"https://github.com/cakephp/cakephp/commit/5e60cc5d182e6131e3fbdfdf69f49d560c9ff78b"},{"type":"WEB","url":"https://bakery.cakephp.org/2015/11/05/cakephp_3015_314_2612_276_released.html"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/cakephp/cakephp/2015-11-05.yaml"},{"type":"PACKAGE","url":"https://github.com/cakephp/cakephp"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:41:07.154891Z"}}