GHSA-vjqc-q4mp-2rvfCritical
CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection
🔗 CVE IDs covered (1)
📋 Description
Impact
The FunctionsBuilder::cast($field, $dataType), extract($part, $expr), datePart($part, $expr), dateAdd($expr, $value, $unit) methods are vulnerable to SQL injection if user controlled data is supplied to the ($dataType / $part / $unit) parameters.
Patches
5.3.7, 5.2.14, 5.1.9, 4.6.5, 4.5.12 contain fixes
Workarounds
Don't provide user controlled data to these functions/parameters.
🎯 Affected products10
- composer/cakephp/database:>= 4.6.0, < 4.6.5
- composer/cakephp/database:>= 5.0.0, < 5.1.9
- composer/cakephp/database:>= 5.2.0, < 5.2.14
- composer/cakephp/database:>= 5.3.0, < 5.3.7
- composer/cakephp/cakephp:< 4.5.12
- composer/cakephp/cakephp:>= 4.6.0, < 4.6.5
- composer/cakephp/cakephp:>= 5.0.0, < 5.1.9
- composer/cakephp/cakephp:>= 5.2.0, < 5.2.14
- composer/cakephp/cakephp:>= 5.3.0, < 5.3.7
- composer/cakephp/database:>= 3.0.0, < 4.5.12
🔗 References (17)
- https://github.com/cakephp/cakephp/security/advisories/GHSA-vjqc-q4mp-2rvf
- https://nvd.nist.gov/vuln/detail/CVE-2026-79752
- https://github.com/cakephp/cakephp/pull/19520
- https://github.com/cakephp/cakephp/pull/19528
- https://github.com/cakephp/cakephp/commit/3349584ca3a891afaff2dbc324d6b1c09fb880f0
- https://github.com/cakephp/cakephp/commit/3f4d13ea4280067f3381ecf935a8bef5b7cdcc2e
- https://github.com/cakephp/cakephp/commit/79e1d6bc6f3a50fa01805579076a02c77370c676
- https://github.com/cakephp/cakephp/commit/8699d6f38e25fe46fcc24f2b698809948e71ad7d
- https://github.com/cakephp/cakephp/commit/ab608711674ac662af7315c5cdf1e0fbe2000e45
- https://github.com/cakephp/cakephp/releases/tag/4.5.12
- https://github.com/cakephp/cakephp/releases/tag/4.6.5
- https://github.com/cakephp/cakephp/releases/tag/5.1.8
- https://github.com/cakephp/cakephp/releases/tag/5.1.9
- https://github.com/cakephp/cakephp/releases/tag/5.2.14
- https://github.com/cakephp/cakephp/releases/tag/5.3.7
- https://github.com/cakephp/cakephp/commit/4730e774bd3b9caa90d67af49e27a12033ec3c71
- https://github.com/advisories/GHSA-vjqc-q4mp-2rvf