Product
Multiple methods in the CakePHP FunctionsBuilder component are vulnerable to SQL injection when user-supplied input is passed to specific functional parameters.