{"id":"GHSA-829q-v5g8-hhxc","aliases":[],"url":"https://o3.security/vulnerability/GHSA-829q-v5g8-hhxc","summary":"CakePHP has incorrect Cross-Site Request Forgery validation","details":"CsrfComponent fails to invalidate requests that are missing both the CSRF token, and CSRF post data.","published":"2023-01-20T23:02:02Z","modified":"2024-11-29T05:49:50.887363Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"cakephp/cakephp","fixedVersion":"3.0.4"}],"fix":{"url":"https://github.com/cakephp/cakephp/commit/522ed2f1fb49b00001c1ef8815a6feda790d61dd","label":"cakephp/cakephp@522ed2f"},"references":[{"type":"WEB","url":"https://github.com/cakephp/cakephp/commit/522ed2f1fb49b00001c1ef8815a6feda790d61dd"},{"type":"WEB","url":"https://bakery.cakephp.org/2015/05/07/cakephp_3_0_4_released.html"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/cakephp/cakephp/2015-05-07.yaml"},{"type":"PACKAGE","url":"https://github.com/cakephp/cakephp"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:49:50.887363Z"}}