Vulnerabilities
Vulnerable Software
Cakephp:  >> Cakephp  >> 4.0.8  Security Vulnerabilities
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string parameter. This issue is fixed in versions 2.11.1, 3.3.6, and 4.1.1.
CVSS Score
5.1
EPSS Score
0.003
Published
2026-07-09
A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to an arbitrary string that is not in the list of request methods that CakePHP checks. Additionally, the route middleware does not verify that this overriden method (which can be an arbitrary string) is actually an HTTP method.
CVSS Score
8.8
EPSS Score
0.006
Published
2021-01-26


Contact Us

Shodan ® - All rights reserved