← Vulnerability feed

Vulnerability record · CVE-2010-4335 · published 14 January 2011

CVE-2010-4335: CakePHP _validatePost unserialize flaw enables remote code execution

Cakefoundation · Cakephp

The _validatePost function in CakePHP's security component passes the attacker-controlled data[_Token][fields] value to unserialize without validation. A remote attacker can use this to alter the internal Cake cache and cause arbitrary local files to be executed. The flaw affects CakePHP 1.3.x through 1.3.5 and 1.2.8.

7.5 CVSS 2.0 High EPSS 55% · top 1.0% CWE-20 · Improper input validation
7.5CVSS 2.0 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
14References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though not in CISA KEV.

What it is

The _validatePost function in CakePHP's security component passes the attacker-controlled data[_Token][fields] value to unserialize without validation. A remote attacker can use this to alter the internal Cake cache and cause arbitrary local files to be executed. The flaw affects CakePHP 1.3.x through 1.3.5 and 1.2.8.

Impact

An unauthenticated remote attacker can modify the framework's internal cache and achieve arbitrary code execution on the server. This gives full control over the application and potentially the host.

Attack surface

Reached over the network through crafted HTTP requests containing a malicious data[_Token][fields] value; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Public exploit code exists (references tagged Exploit, including a Packet Storm script and an Exploit-DB entry), and EPSS is 0.55204 (99th percentile), though the CVE is not listed in CISA KEV.

What to do

  • Upgrade CakePHP to a version containing the fix commit e431e86aa4301ced4273dc7919b59362cbb353cb or later.
  • If immediate upgrade is not possible, avoid passing untrusted input to unserialize in the security component and validate the data[_Token][fields] parameter strictly.
  • Restrict write access to the Cake cache directory and monitor it for unexpected changes.
  • Apply the vendor advisory guidance from Secunia advisory 42211.

Detection

  • Inspect web requests for unusual or oversized data[_Token][fields] values, especially serialized PHP object payloads.
  • Monitor the Cake cache directory for unexpected file creation or modification.
  • Alert on outbound or local file execution activity originating from the web server process following requests to CakePHP endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-4335 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-22727Cakephp sql injection vulnerabilityCakePHP is a development framework for PHP web apps. In affected versions the `Cake\Database\Query::limit()` and `Cake\Database\Query::offset()` meth…EPSS 0.86%8.8CVE-2020-35239Cakephp cross-site request forgery vulnerabilityA vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CS…EPSS 0.60%8.8CVE-2015-8379Cakephp cross-site request forgery vulnerabilityCakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.EPSS 1.4%7.5CVE-2019-11458Cakephp deserialization of untrusted data vulnerabilityAn issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can trigger arbitrary file overwr…EPSS 2.0%7.5CVE-2016-4793Cakephp improper input validation vulnerabilityThe clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.EPSS 5.1%7.5CVE-2012-4399Cakefoundation cakephp xml external entity (xxe) vulnerabilityThe Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external e…EPSS 12%5.4CVE-2026-23643Cakephp cross-site scripting vulnerabilityCakePHP is a rapid development framework for PHP. The PaginatorHelper::limitControl() method has a cross-site-scripting vulnerability via query strin…EPSS 0.29%5.1CVE-2026-55590Cakephp open redirect vulnerabilityCakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, …EPSS 0.49%

Source: NIST National Vulnerability Database (record CVE-2010-4335), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.