Cross-site request forgery In cakephp/cakephp
Description
Cross-Site Request Forgery in CakePHP CakePHP before 4.0.6 and 3.10.3 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 4.0.6, 3.10.3 | ||
debian 11 | - |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2.