Description
CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.
Remediation
References
Related Vulnerabilities
Apache Tomcat Improper Authentication Vulnerability (CVE-2012-5886)
MySQL CVE-2021-2293 Vulnerability (CVE-2021-2293)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-20099)
Joomla! Core Security Bypass (1.6.0 - 3.9.24)
WordPress Plugin FV Flowplayer Video Player Multiple Vulnerabilities (7.3.14.727)