CVE-2019-11458

HIGH7.5EPSS 0.53%

Unsafe deserialization in SmtpTransport in CakePHP

Published: 12/2/2019Modified: 5/29/2025
Also known as:GHSA-qhrx-hcm6-pmrw

Description

An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References (10)