cakephp/cakephp is vulnerable to Improper Authorization
50
Medium Risk
Certain versions of CakePHP could incorrectly generate SQL when embedding a subquery that was already executed. This could cause access control conditions (WHERE clauses, bindings) to be lost or mishandled, leading to unauthorized data exposure or bypassing logic checks.
You are affected if you are using a version that falls within the vulnerable range.
cakephp/cakephp is vulnerable to Improper Authorization in versions 3.2.6 - 5.2.7.
Upgrade cake/cakephp to the patch version. A patch for 4.X is currently unavailable.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant