logo

Database

Cross-site request forgery In cakephp/cakephp

Description

CakePHP might allow remote attackers to bypass CSRF protection mechanism via the _method parameter CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions