Cross-site Request Forgery (CSRF) The advisory has been revoked - it doesn't affect any version of package cakephp Open this link in a new tab


    Threat Intelligence

    EPSS 0.05% (21st percentile)
Expand this section
NVD
4.3 medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-DEBIANUNSTABLE-CAKEPHP-575229
  • published 2 Jul 2020
  • disclosed 30 Jun 2020

Amendment

The Debian security team deemed this advisory irrelevant for Debian:unstable.

NVD Description

Note: Versions mentioned in the description apply only to the upstream cakephp package and not the cakephp package as distributed by Debian.

CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.