Vulnerabilities > Cakephp > Cakephp > 1.2.4

DATE CVE VULNERABILITY TITLE RISK
2017-01-23 CVE-2016-4793 Improper Input Validation vulnerability in Cakephp
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
network
low complexity
cakephp CWE-20
7.5