CVE-2020-35239
Last modified
CVE-2020-35239 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to an arbitrary string that is not in the list of request methods that CakePHP checks. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to an arbitrary string that is not in the list of request methods that CakePHP checks. Additionally, the route middleware does not verify that this overriden method (which can be an arbitrary string) is actually an HTTP method.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cakephp | Cakephp | >= 4.0.0, <= 4.1.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-35239?
How severe is CVE-2020-35239?
How do I fix CVE-2020-35239?
Are you affected by CVE-2020-35239?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
