An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwriting upon destruction.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| cakephp/cakephp(Packagist) | 3.0.0 | 3.5.18 | N/A |
| cakephp/cakephp(Packagist) | 3.6.0 | 3.6.15 | N/A |
| cakephp/cakephp(Packagist) | 3.7.0 | 3.7.7 | N/A |
CVSS Metrics