{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cakephp/database--4.5.12--4.6.0--4.6.5--5.0.0--5.1.9--5.2.0--5.2.14--5.3.0--5.3.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-79752"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cakephp/database (\u003c 4.5.12, \u003e= 4.6.0 \u003c 4.6.5, \u003e= 5.0.0 \u003c 5.1.9, \u003e= 5.2.0 \u003c 5.2.14, \u003e= 5.3.0 \u003c 5.3.7)","cakephp/cakephp (\u003c 4.5.12, \u003e= 4.6.0 \u003c 4.6.5, \u003e= 5.0.0 \u003c 5.1.9, \u003e= 5.2.0 \u003c 5.2.14, \u003e= 5.3.0 \u003c 5.3.7)"],"_cs_severities":["critical"],"_cs_tags":["sql-injection","vulnerability","web-application"],"_cs_type":"advisory","_cs_vendors":["CakePHP"],"content_html":"\u003cp\u003eThe CakePHP framework contains a critical SQL injection vulnerability (CVE-2026-79752) affecting the \u003ccode\u003eFunctionsBuilder\u003c/code\u003e component. The vulnerability exists in the \u003ccode\u003ecast($field, $dataType)\u003c/code\u003e, \u003ccode\u003eextract($part, $expr)\u003c/code\u003e, \u003ccode\u003edatePart($part, $expr)\u003c/code\u003e, and \u003ccode\u003edateAdd($expr, $value, $unit)\u003c/code\u003e methods. An attacker can exploit this flaw by supplying malicious user-controlled input to the \u003ccode\u003e$dataType\u003c/code\u003e, \u003ccode\u003e$part\u003c/code\u003e, or \u003ccode\u003e$unit\u003c/code\u003e parameters of these functions. If an application fails to sanitize or validate input before passing it to these parameters, an attacker can manipulate the resulting SQL query, potentially leading to unauthorized database access, data exfiltration, or modification. This issue impacts multiple versions of the \u003ccode\u003ecakephp/database\u003c/code\u003e and \u003ccode\u003ecakephp/cakephp\u003c/code\u003e packages across the 4.x and 5.x branches. Organizations using these versions are encouraged to update to the patched releases immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated or authenticated attackers to execute arbitrary SQL commands against the database used by the CakePHP application. The impact includes the potential for full database compromise, unauthorized disclosure of sensitive information, and loss of data integrity. All applications leveraging the vulnerable \u003ccode\u003eFunctionsBuilder\u003c/code\u003e methods with dynamic user input are at risk, regardless of the sector.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003ecakephp/database\u003c/code\u003e and \u003ccode\u003ecakephp/cakephp\u003c/code\u003e packages to the versions containing the security fix: 5.3.7, 5.2.14, 5.1.9, 4.6.5, or 4.5.12.\u003c/li\u003e\n\u003cli\u003eAudit existing application code to identify any instances where user-supplied data is passed directly into \u003ccode\u003eFunctionsBuilder\u003c/code\u003e methods without strict validation or allowlisting.\u003c/li\u003e\n\u003cli\u003eImplement a temporary workaround by ensuring that all user-supplied data passed to \u003ccode\u003ecast\u003c/code\u003e, \u003ccode\u003eextract\u003c/code\u003e, \u003ccode\u003edatePart\u003c/code\u003e, and \u003ccode\u003edateAdd\u003c/code\u003e parameters is hardcoded or strictly filtered against a known-safe list of values before function invocation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T01:10:30Z","date_published":"2026-09-18T01:10:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cakephp-sql-injection/","summary":"Multiple methods in the CakePHP FunctionsBuilder component are vulnerable to SQL injection when user-supplied input is passed to specific functional parameters.","title":"SQL Injection Vulnerability in CakePHP FunctionsBuilder","url":"https://feed.craftedsignal.io/briefs/2026-09-cakephp-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cakephp/Database (\u003c 4.5.12, \u003e= 4.6.0 \u003c 4.6.5, \u003e= 5.0.0 \u003c 5.1.9, \u003e= 5.2.0 \u003c 5.2.14, \u003e= 5.3.0 \u003c 5.3.7)","version":"https://jsonfeed.org/version/1.1"}