The clientIp function in CakePHP 3.2.4 and previous versions allows remote malicious users to spoof their IP via the CLIENT-IP HTTP header.
cakephp cakephp