Junglewise Threat Intelligence

CVE-2015-8379: CakePHP might allow remote attackers to bypass CSRF protection mechanism via the _method parameter

CVE-2015-8379 · Severity: low · CVSS 3 · Published 2022-05-14

Technologies: cakephp/cakephp (Packagist). Vendors: Packagist.

Executive brief

CakePHP might allow remote attackers to bypass CSRF protection mechanism via the _method parameter

Affected products

  • Packagist cakephp/cakephp

Related threats