CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
{ "binaries": [ { "binary_version": "2.8.0-1", "binary_name": "cakephp" }, { "binary_version": "2.8.0-1", "binary_name": "cakephp-scripts" } ] }
{ "binaries": [ { "binary_version": "2.10.11-2", "binary_name": "cakephp" }, { "binary_version": "2.10.11-2", "binary_name": "cakephp-scripts" } ] }
{ "binaries": [ { "binary_version": "2.10.24-1", "binary_name": "cakephp" }, { "binary_version": "2.10.24-1", "binary_name": "cakephp-scripts" } ] }