CakePHP has incorrect Cross-Site Request Forgery validation
Moderate severity
GitHub Reviewed
Published
Jan 20, 2023
to the GitHub Advisory Database
•
Updated Jan 20, 2023
Description
Published to the GitHub Advisory Database
Jan 20, 2023
Reviewed
Jan 20, 2023
Last updated
Jan 20, 2023
CsrfComponent fails to invalidate requests that are missing both the CSRF token, and CSRF post data.
References