Lucene search

K
osvGoogleOSV:GHSA-J33J-FG2G-MCV2
HistoryFeb 10, 2022 - 10:27 p.m.

Cross-Site Request Forgery in CakePHP

2022-02-1022:27:58
Google
osv.dev
10
cakephp
cross-site request forgery
csrf token
xss
security vulnerability

EPSS

0.001

Percentile

21.6%

CakePHP before 4.0.6 and 3.10.3 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.

EPSS

0.001

Percentile

21.6%