4.3
CVSSv2

CVE-2020-15400

Published: 30/06/2020 Updated: 21/07/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

CakePHP prior to 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cakefoundation cakephp

Vendor Advisories

Debian Bug report logs - #985673 CVE-2020-15400 Package: cakephp; Maintainer for cakephp is Dmitry Smirnov <onlyjob@debianorg>; Source for cakephp is src:cakephp (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 21 Mar 2021 19:09:02 UTC Severity: important Tags: security, upstream ...