cakephp/cakephp is vulnerable to Open Redirect
63
Medium Risk
Affected versions of this package are affected by Open redirect due to improper handling of encoded forward slashes (%2F) when reading request URIs. These paths may be misinterpreted as a single slash (/), resulting in unexpected routing behavior. This problem could potentially be exploited to create open redirect attacks, allowing an attacker to redirect users to malicious sites.
You are affected if you are using a version that falls within the vulnerable range.
cakephp/cakephp is vulnerable to Open Redirect in versions 5.0.0 - 5.1.2 and 3.0.0 - 4.5.8.
Upgrade the cakephp/cakephp library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant