Логотип exploitDog
bind:CVE-2020-35239
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-35239

Количество 4

Количество 4

ubuntu логотип

CVE-2020-35239

около 5 лет назад

A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to an arbitrary string that is not in the list of request methods that CakePHP checks. Additionally, the route middleware does not verify that this overriden method (which can be an arbitrary string) is actually an HTTP method.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-35239

около 5 лет назад

A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to an arbitrary string that is not in the list of request methods that CakePHP checks. Additionally, the route middleware does not verify that this overriden method (which can be an arbitrary string) is actually an HTTP method.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-35239

около 5 лет назад

A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The Cs ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-9pgx-pf36-w46r

больше 3 лет назад

CakePHP allows method override parameters to bypass CSRF checks

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-35239

A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to an arbitrary string that is not in the list of request methods that CakePHP checks. Additionally, the route middleware does not verify that this overriden method (which can be an arbitrary string) is actually an HTTP method.

CVSS3: 8.8
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-35239

A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to an arbitrary string that is not in the list of request methods that CakePHP checks. Additionally, the route middleware does not verify that this overriden method (which can be an arbitrary string) is actually an HTTP method.

CVSS3: 8.8
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-35239

A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The Cs ...

CVSS3: 8.8
0%
Низкий
около 5 лет назад
github логотип
GHSA-9pgx-pf36-w46r

CakePHP allows method override parameters to bypass CSRF checks

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу