logo

Database

Lack of data validation - Path Traversal In cakephp/cakephp

Description

CakePHP: View::element() is missing a path containment check

Impact

View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server.

Patches

Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11.

Workarounds

If developers are not using user-supplied data in element names, no action is required.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions