CVE-2016-4793: Input Validation
Published Jan 23, 2017
·Updated
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
Affected Software
1 affected component
CakePHP CakePHP<=3.2.4
Remediation
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-4793?
CVE-2016-4793 has a moderate severity rating as it allows remote attackers to spoof IP addresses.
2
How do I fix CVE-2016-4793?
To fix CVE-2016-4793, upgrade CakePHP to version 3.2.5 or later where the vulnerability is addressed.
3
What is the impact of CVE-2016-4793 on my application?
The impact of CVE-2016-4793 includes the potential for attackers to impersonate legitimate users by spoofing their IP addresses.
4
Which versions of CakePHP are affected by CVE-2016-4793?
CVE-2016-4793 affects all versions of CakePHP up to and including 3.2.4.
5
Is CVE-2016-4793 publicly known?
Yes, CVE-2016-4793 is publicly known and documented in various security advisories.