cakephp/cakephp is vulnerable to Improper Authorization
50
Medium Risk
Certain versions of CakePHP could incorrectly generate SQL when embedding a subquery that was already executed. This could cause access control conditions (WHERE clauses, bindings) to be lost or mishandled, leading to unauthorized data exposure or bypassing logic checks.
You are affected if you are using a version that falls within the vulnerable range.
cakephp/cakephp is vulnerable to Improper Authorization in versions 3.2.6 - 5.2.7.
Upgrade cake/cakephp to the patch version. A patch for 4.X is currently unavailable.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant