CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1.6, 5.2.0 through 5.2.12, and 5.3.0 through 5.3.5, View::_getElementFileName() does not check that the resolved element path is within the application/plugin view template paths. When element names are created with specifically crafted user-supplied data this weakness can be leveraged to include other PHP files on the server. Patched releases are available in 5.3.6, 5.2.13, 5.1.7, 4.6.4, and 4.5.11.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-17 22:16
Updated : 2026-06-23 15:44
NVD link : CVE-2026-48820
Mitre link : CVE-2026-48820
CVE.ORG link : CVE-2026-48820
JSON object : View
Products Affected
No product.
