{"id":"GHSA-xwhj-pqcg-8rcr","aliases":[],"url":"https://o3.security/vulnerability/GHSA-xwhj-pqcg-8rcr","summary":"CakePHP vulnerable to Cross-site Scripting in some development error pages","details":"CakePHP 3.4 prior to 3.4.14, 3.5 prior to 3.5.17, and 3.6 prior to 3.6.4 contains a cross-site-scripting (XSS) vulnerability in the development only `missing route` and `duplicate named route` error pages.","published":"2023-01-20T23:35:17Z","modified":"2024-11-29T05:41:07.087696Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"3.4.14"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"3.5.17"},{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"3.6.4"}],"fix":{"url":"https://github.com/cakephp/cakephp/commit/1ea0c87de729e0dcd53eb6fe3bc86ba739121d8e","label":"cakephp/cakephp@1ea0c87"},"references":[{"type":"WEB","url":"https://github.com/cakephp/cakephp/commit/1ea0c87de729e0dcd53eb6fe3bc86ba739121d8e"},{"type":"WEB","url":"https://bakery.cakephp.org/2018/05/20/cakephp_364_3517_3414_released.html"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/cakephp/cakephp/2018-05-20.yaml"},{"type":"PACKAGE","url":"https://github.com/cakephp/cakephp"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:41:07.087696Z"}}