MEDIUM

CVE-2026-48820

2026-06-17 CVSS v4.0
CVSS
6.3

Description

CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11.

Summary dbcve.org

CakePHP's View::_getElementFileName() method fails to validate that resolved element paths stay within allowed application/plugin view template directories. This allows path traversal via crafted element names (e.g., using ../../ sequences) to include arbitrary PHP files on the server, resulting in potential local file inclusion.

Mitigation

Upgrade CakePHP to patched versions (5.3.6, 5.2.13, 5.1.7, 4.6.4, or 4.5.11). If immediate patching is not feasible, implement strict input validation on element name parameters to reject path traversal sequences.

Weakness (CWE)

CWE-22 Path Traversal
CWE-98 PHP File Inclusion (RFI/LFI)

EPSS Score

0.26%
Probability of exploitation in next 30 days
17.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE