CVE-2020-15400: XSS
Published Jun 30, 2020
·Updated
CakePHP before 4.0.6 and 3.10.3 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
Other sources
CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
Affected Software
3 affected componentsFixes available
composer/cakephp/cakephp<3.10.3
3.10.3
composer/cakephp/cakephp>=4.0.0<4.0.6
4.0.6
Cakefoundation Cakephp<4.0.6
Event History
Jun 30, 2020
CVE Published
via MITRE·11:42 AM
Data Sourced
via MITRE·11:42 AM
Description
Feb 10, 2022
Advisory Published
10:27 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-15400?
The severity of CVE-2020-15400 is medium.
2
How does CVE-2020-15400 affect CakePHP?
CVE-2020-15400 affects CakePHP versions before 4.0.6 and 3.10.3.
3
What is the vulnerability in CVE-2020-15400?
The vulnerability in CVE-2020-15400 is mishandling of CSRF token generation in CakePHP.
4
Can CVE-2020-15400 be exploited remotely?
Yes, CVE-2020-15400 might be remotely exploitable in conjunction with XSS.
5
How can I fix CVE-2020-15400?
To fix CVE-2020-15400, update your CakePHP installation to version 4.0.6 or 3.10.3.