Description
CakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query string parameter manipulation. This issue has been fixed in 5.2.12 and 5.3.1.
Remediation
References
Related Vulnerabilities
Zope Web Application Server Other Vulnerability (CVE-2002-0687)
ownCloud Improper Authentication Vulnerability (CVE-2023-49105)
WordPress Plugin LittleBot ACH for Stripe + Plaid Unspecified Vulnerability (1.2.6)
WordPress Plugin Request a Quote Cross-Site Scripting (2.3.4)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-0059)