CVE-2010-4335 is a critical vulnerability affecting CakePHP versions 1.3.x through 1.3.5 and 1.2.8, where a flaw in the _validatePost function allows remote attackers to manipulate the internal Cake cache. By sending a specially crafted data[_Token][fields] value, attackers can leverage an unserialize vulnerability to execute arbitrary code, potentially leading to the execution of local files. This vulnerability carries a high CVSS score of 7.5, indicating a severe risk with low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, exploit intelligence confirms the existence of public exploit code, including a Metasploit module and ExploitDB entries, demonstrating its exploitability. Despite the availability of exploits, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.0CPE matchmatch criteria | cpe:2.3:a:cakefoundation:cakephp:1.3.0:*:*:*:*:*:*:* | ||
1.2.8CPE matchmatch criteria | cpe:2.3:a:cakephp:cakephp:1.2.8:*:*:*:*:*:*:* | ||
1.3CPE matchmatch criteria | cpe:2.3:a:cakephp:cakephp:1.3:dev:*:*:*:*:*:* | ||
1.3.0CPE matchmatch criteria | cpe:2.3:a:cakephp:cakephp:1.3.0:alpha:*:*:*:*:*:* | ||
1.3.0CPE matchmatch criteria | cpe:2.3:a:cakephp:cakephp:1.3.0:beta:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.