← Back

CVE-2015-8379

nvd nist
Published: Jan 26, 2016Modified: May 6, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.

Affected (137)

Products: Cakephp: Cakephp
1 product
Cakephp
Configuration A
137 vulnerable
Vulnerable SoftwareAffected Versions
Cakephp
Version 2.0.0
Version 2.0.0 alpha
Version 2.0.0 beta
Version 2.0.0 dev
Version 2.0.0 rc1
Version 2.0.0 rc2
Version 2.0.0 rc3
Version 2.0.1
Version 2.0.2
Version 2.0.3
Version 2.0.4
Version 2.0.5
Version 2.0.6
Version 2.1.0
Version 2.1.0 alpha
Version 2.1.0 beta
Version 2.1.0 rc1
Version 2.1.1
Version 2.1.2
Version 2.1.3
Version 2.1.4
Version 2.1.5
Version 2.2.0
Version 2.2.0 beta
Version 2.2.0 rc1
Version 2.2.0 rc2
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.2.4
Version 2.2.5
Version 2.2.6
Version 2.2.7
Version 2.2.8
Version 2.2.9
Version 2.3.0
Version 2.3.0 beta
Version 2.3.0 rc1
Version 2.3.0 rc2
Version 2.3.10
Version 2.3.1
Version 2.3.2
Version 2.3.3
Version 2.3.4
Version 2.3.5
Version 2.3.6
Version 2.3.7
Version 2.3.8
Version 2.3.9
Version 2.4.0
Version 2.4.0 beta
Version 2.4.0 rc1
Version 2.4.0 rc2
Version 2.4.10
Version 2.4.1
Version 2.4.2
Version 2.4.3
Version 2.4.4
Version 2.4.5
Version 2.4.6
Version 2.4.7
Version 2.4.8
Version 2.4.9
Version 2.5.0
Version 2.5.0 beta
Version 2.5.0 rc1
Version 2.5.0 rc2
Version 2.5.1
Version 2.5.2
Version 2.5.3
Version 2.5.4
Version 2.5.5
Version 2.5.6
Version 2.5.7
Version 2.5.8
Version 2.5.9
Version 2.6.0
Version 2.6.0 beta
Version 2.6.0 rc1
Version 2.6.10
Version 2.6.11
Version 2.6.12
Version 2.6.1
Version 2.6.2
Version 2.6.3
Version 2.6.4
Version 2.6.5
Version 2.6.6
Version 2.6.7
Version 2.6.8
Version 2.6.9
Version 2.7.0
Version 2.7.0 rc1
Version 2.7.1
Version 2.7.2
Version 2.7.3
Version 2.7.4
Version 2.7.5
Version 2.7.6
Version 2.7.7
Version 2.7.8
Version 2.7.9
Version 2.8.0 rc1
Version 3.0.0
Version 3.0.0 alpha1
Version 3.0.0 alpha2
Version 3.0.0 beta1
Version 3.0.0 beta2
Version 3.0.0 beta3
Version 3.0.0 dev1
Version 3.0.0 dev2
Version 3.0.0 dev3
Version 3.0.0 rc1
Version 3.0.0 rc2
Version 3.0.10
Version 3.0.11
Version 3.0.12
Version 3.0.13
Version 3.0.14
Version 3.0.15
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.4
Version 3.0.5
Version 3.0.6
Version 3.0.7
Version 3.0.8
Version 3.0.9
Version 3.1.0
Version 3.1.0 beta1
Version 3.1.0 beta2
Version 3.1.0 rc1
Version 3.1.1
Version 3.1.2
Version 3.1.3
Version 3.1.4

Timeline

No history available yet.