CVE-2016-4793

high
Published 2017-01-23 · Modified 2024-02-18
CVSS v3
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2
5.0
VIR risk
7.5

Description

CakePHP allows remote attackers to spoof their IP

Predictions

Exploit likelihood
83%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2016-4793

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://bakery.cakephp.org/2016/03/13/cakephp_2613_2711_282_3017_3112_325_released.html

OS impact

OSVersionStatusFixed in
debian debianbullseyefixed2.8.3-1

Package impact

EcosystemPackageVulnerableFixed
php Packagistcakephp/cakephp>=1.2.0,<2.6.132.6.13
php Packagistcakephp/cakephp>=2.7.0-rc1,<2.7.112.7.11
php Packagistcakephp/cakephp>=2.8.0-rc1,<2.8.22.8.2
php Packagistcakephp/cakephp>=3.0.0-rc1,<3.0.173.0.17
php Packagistcakephp/cakephp>=3.1.0-beta1,<3.1.123.1.12
php Packagistcakephp/cakephp>=3.2.0-rc1,<3.2.53.2.5

Application impact

VendorProductVersionsFixed
cakephpcakephp{"endIncluding":"3.2.4"}

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.