Impact
CakePHP’s FunctionsBuilder methods can incorporate user‑controlled dataType, part, or unit values directly into SQL query fragments without escaping. An attacker can thus inject arbitrary SQL statements, resulting in confidentiality loss, data tampering, or denial of service through the privileges of the database connection. The vulnerability is an instance of SQL injection (CWE‑89).
Affected Systems
All CakePHP releases older than 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7 are vulnerable. In particular, the affected functions are FunctionsBuilder::cast, ::extract, ::datePart, and ::dateAdd located in src/Database/FunctionsBuilder.php.
Risk and Exploitability
The CVSS score of 9.2 denotes a critical severity and indicates that exploitation could be highly damaging if the attacker can supply input to the vulnerable methods. Although the EPSS score is not available, the high base score suggests that exploitation scenarios are plausible. The vulnerability is not yet listed in CISA’s KEV catalog, but no public exploits are reported, so the exploitability largely depends on the attacker’s ability to inject data into the application’s query‑building logic.
OpenCVE Enrichment
Github GHSA