Executive brief
CakePHP might allow remote attackers to bypass CSRF protection mechanism via the _method parameter
Affected products
- Packagist cakephp/cakephp
Junglewise Threat Intelligence
CVE-2015-8379 · Severity: low · CVSS 3 · Published 2022-05-14
Technologies: cakephp/cakephp (Packagist). Vendors: Packagist.
CakePHP might allow remote attackers to bypass CSRF protection mechanism via the _method parameter