CVE-2020-35239: CSRF

Published Jan 20, 2021
·
Updated

A vulnerability exists in CakePHP versions 4.0.x through 4.1.3. The CsrfProtectionMiddleware component allows method override parameters to bypass CSRF checks by changing the HTTP request method to an arbitrary string that is not in the list of request methods that CakePHP checks. Additionally, the route middleware does not verify that this overriden method (which can be an arbitrary string) is actually an HTTP method.

Affected Software

2 affected components
CakePHP CakePHP>=4.0.0<=4.1.3
Cakefoundation Cakephp>=4.0.0<=4.1.3

Event History

Jan 20, 2021
CVE Published
via MITRE·11:37 PM
Data Sourced
via MITRE·11:37 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2020-35239?

CVE-2020-35239 has been assigned a medium severity rating due to its potential to bypass CSRF protections.

2

How do I fix CVE-2020-35239?

To fix CVE-2020-35239, you should upgrade CakePHP to version 4.1.4 or later.

3

What versions of CakePHP are affected by CVE-2020-35239?

CVE-2020-35239 affects CakePHP versions 4.0.0 through 4.1.3.

4

What type of attacks can exploit CVE-2020-35239?

CVE-2020-35239 can be exploited to bypass CSRF protections, which may lead to unauthorized actions being executed on behalf of authenticated users.

5

Is there a workaround for CVE-2020-35239 if I cannot upgrade?

There is no official workaround for CVE-2020-35239, so upgrading to a patched version is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203