Cross-site Scripting (XSS) Affecting cakephp/cakephp package, versions >=3.6.0, <3.6.4>=3.4.0, <3.4.14>=3.5.0, <3.5.17


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PHP-CAKEPHPCAKEPHP-72148
  • published22 May 2018
  • disclosed21 May 2018
  • creditNacer

Introduced: 21 May 2018

CVE NOT AVAILABLE CWE-79  (opens in a new tab)

How to fix?

Upgrade cakephp/cakephp to versions 3.6.4, 3.4.14, 3.5.17 or higher.

Overview

cakephp/cakephp is a rapid development framework for PHP which uses commonly known design patterns like Associative Data Mapping, Front Controller, and MVC.

Affected versions of this package are vulnerable to Cross-site Scripting attacks in the development only missing route and duplicate named route error pages.

Details

<>

References

CVSS Scores

version 3.1