{"id":"GHSA-829q-v5g8-hhxc","summary":"CakePHP has incorrect Cross-Site Request Forgery validation","details":"CsrfComponent fails to invalidate requests that are missing both the CSRF token, and CSRF post data.","modified":"2024-11-29T05:49:50.887363Z","published":"2023-01-20T23:02:02Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-01-20T23:02:02Z","nvd_published_at":null,"cwe_ids":["CWE-352"]},"references":[{"type":"WEB","url":"https://github.com/cakephp/cakephp/commit/522ed2f1fb49b00001c1ef8815a6feda790d61dd"},{"type":"WEB","url":"https://bakery.cakephp.org/2015/05/07/cakephp_3_0_4_released.html"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/cakephp/cakephp/2015-05-07.yaml"},{"type":"PACKAGE","url":"https://github.com/cakephp/cakephp"}],"affected":[{"package":{"name":"cakephp/cakephp","ecosystem":"Packagist","purl":"pkg:composer/cakephp/cakephp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.0.4"}]}],"versions":["3.0.0","3.0.1","3.0.2","3.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-829q-v5g8-hhxc/GHSA-829q-v5g8-hhxc.json"}}],"schema_version":"1.9.0"}