logo

Database

Cross-site request forgery In cakephp/cakephp

Description

Cross-Site Request Forgery in CakePHP CakePHP before 4.0.6 and 3.10.3 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions