Improper authorization control for web services In cakephp/cakephp
Description
CakePHP allows direct access of prefixed controller actions Unconventional URL paths would allow direct access to prefixed actions without setting the correct request parameters.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 2.0.99, 2.1.99, 2.2.99, 2.3.99, 2.4.99, 2.5.9, 2.6.11, 2.7.2 |
Aliases
1.
References
1. 2. 3. 4. 5. 6.