logo

Database

Reflected cross-site scripting (XSS) In cakephp/cakephp

Description

CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting

Impact

The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation.

Patches

This issue has been fixed in 5.2.12 and 5.3.1

Workarounds

If you are unable to upgrade, you should avoid using Paginator::limitControl() until you can upgrade.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions

Does your application use this vulnerable software?

During the free trial, our tools assess your application, identify vulnerabilities, and provide recommendations for their remediation.

FLAT-9K611 – Vulnerability