« Volver al listado

CVE-2026-23643

Estado: AnalizadaMedia (5.4)—

CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-23643",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-23643",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-16T21:21:32.578620Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "cakephp",
          "product": "cakephp",
          "versions": [
            {
              "status": "affected",
              "version": ">= 5.2.10, < 5.2.12"
            },
            {
              "status": "affected",
              "version": ">= 5.3.0, < 5.3.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-01-16T21:15:51.543",
  "references": [
    {
      "url": "https://bakery.cakephp.org/2026/01/14/cakephp_5212.html",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/cakephp/cakephp/commit/c842e7f45d85696e6527d8991dd72f525ced955f",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/cakephp/cakephp/issues/19172",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/cakephp/cakephp/releases/tag/5.2.12",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/cakephp/cakephp/releases/tag/5.3.1",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/cakephp/cakephp/security/advisories/GHSA-qh8m-9qxx-53m5",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1."
    },
    {
      "lang": "es",
      "value": "CakePHP es un framework de desarrollo rápido para PHP. El método PaginatorHelper::limitControl() tiene una vulnerabilidad de cross-site-scripting a través de la manipulación de parámetros de cadena de consulta. Este problema ha sido solucionado en 5.2.12 y 5.3.1."
    }
  ],
  "lastModified": "2026-06-17T10:21:52.843",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DACDDE3A-55B3-43F0-A030-07372FDEC42B",
              "versionEndExcluding": "5.2.12",
              "versionStartIncluding": "5.2.10"
            },
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:5.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56DEA383-8A1A-47C5-B1B9-BB4FEF91024D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}