CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
{ "binaries": [ { "binary_name": "cakephp", "binary_version": "2.8.0-1" }, { "binary_name": "cakephp-scripts", "binary_version": "2.8.0-1" } ] }
{ "binaries": [ { "binary_name": "cakephp", "binary_version": "2.10.11-2" }, { "binary_name": "cakephp-scripts", "binary_version": "2.10.11-2" } ] }
{ "binaries": [ { "binary_name": "cakephp", "binary_version": "2.10.24-1" }, { "binary_name": "cakephp-scripts", "binary_version": "2.10.24-1" } ] }