CVE-2015-8379Cross-Site Request Forgery in Cakephp

Severity
8.8HIGHNVD
EPSS
0.1%
top 81.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 26
Latest updateMay 14

Description

CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

debiandebian/cakephp< cakephp 2.8.0-1 (bullseye)
Packagistcakephp/cakephp2.0.0-alpha3.1.5
Debiancakephp/cakephp< 2.8.0-1
NVDcakephp/cakephp100 versions+99

Patches

🔴Vulnerability Details

3
GHSA
CakePHP might allow remote attackers to bypass CSRF protection mechanism via the _method parameter2022-05-14
OSV
CakePHP might allow remote attackers to bypass CSRF protection mechanism via the _method parameter2022-05-14
OSV
CVE-2015-8379: CakePHP 22016-01-26

📋Vendor Advisories

1
Debian
CVE-2015-8379: cakephp - CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF...2015