Lack of data validation - Path Traversal In cakephp/cakephp
Description
CakePHP: View::element() is missing a path containment check
Impact
View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server.
Patches
Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11.
Workarounds
If developers are not using user-supplied data in element names, no action is required.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 5.3.6, 5.2.13, 5.1.7, 4.6.4, 4.5.11 | ||
debian 11 | - |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1.