Packagist · cakephp/cakephp
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
The FunctionsBuilder::jsonValue($field, $jsonPath) methods with the Postgres driver is vulnerable to SQL injection if user controlled data is supplied to the $jsonPath parameter.
5.1.10, 5.2.15, 5.3.7
Don't provide user controlled data to these functions/parameters.
Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.
Check my repoSources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.