Security Advisory
CVE-2016-4793
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.