CVE-2020-15400Cross-site Scripting in Cakephp

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 75.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 30
Latest updateFeb 10

Description

CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

Packagistcakephp/cakephp4.0.04.0.6+1

🔴Vulnerability Details

3
GHSA
Cross-Site Request Forgery in CakePHP2022-02-10
OSV
Cross-Site Request Forgery in CakePHP2022-02-10
OSV
CVE-2020-15400: CakePHP before 42020-06-30

📋Vendor Advisories

1
Debian
CVE-2020-15400: cakephp - CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely ex...2020