CVE-2016-4793

Publication date

2017-01-23 21:00:00

Family

mitre

State

PUBLISHED

Description

The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.