{"id":"GHSA-xwhj-pqcg-8rcr","summary":"CakePHP vulnerable to Cross-site Scripting in some development error pages","details":"CakePHP 3.4 prior to 3.4.14, 3.5 prior to 3.5.17, and 3.6 prior to 3.6.4 contains a cross-site-scripting (XSS) vulnerability in the development only `missing route` and `duplicate named route` error pages.","modified":"2024-11-29T05:41:07.087696Z","published":"2023-01-20T23:35:17Z","database_specific":{"github_reviewed_at":"2023-01-20T23:35:17Z","nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/cakephp/cakephp/commit/1ea0c87de729e0dcd53eb6fe3bc86ba739121d8e"},{"type":"WEB","url":"https://bakery.cakephp.org/2018/05/20/cakephp_364_3517_3414_released.html"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/cakephp/cakephp/2018-05-20.yaml"},{"type":"PACKAGE","url":"https://github.com/cakephp/cakephp"}],"affected":[{"package":{"name":"cakephp/cakephp","ecosystem":"Packagist","purl":"pkg:composer/cakephp/cakephp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.4.0"},{"fixed":"3.4.14"}]}],"versions":["3.4.0","3.4.1","3.4.10","3.4.11","3.4.12","3.4.13","3.4.2","3.4.3","3.4.4","3.4.5","3.4.6","3.4.7","3.4.8","3.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-xwhj-pqcg-8rcr/GHSA-xwhj-pqcg-8rcr.json"}},{"package":{"name":"cakephp/cakephp","ecosystem":"Packagist","purl":"pkg:composer/cakephp/cakephp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.5.0"},{"fixed":"3.5.17"}]}],"versions":["3.5.0","3.5.1","3.5.10","3.5.11","3.5.12","3.5.13","3.5.14","3.5.15","3.5.16","3.5.2","3.5.3","3.5.4","3.5.5","3.5.6","3.5.7","3.5.8","3.5.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-xwhj-pqcg-8rcr/GHSA-xwhj-pqcg-8rcr.json"}},{"package":{"name":"cakephp/cakephp","ecosystem":"Packagist","purl":"pkg:composer/cakephp/cakephp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.6.0"},{"fixed":"3.6.4"}]}],"versions":["3.6.0","3.6.1","3.6.2","3.6.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-xwhj-pqcg-8rcr/GHSA-xwhj-pqcg-8rcr.json"}}],"schema_version":"1.9.0"}