CyberRota Analysis
AI-GeneratedThe CakePHP Authentication plugin prior to versions 2.11.1, 3.3.6, and 4.1.1 is vulnerable to a backslash bypass in the getLoginRedirect() method, which permits attackers to manipulate redirect targets using malicious hostnames via the redirect query string parameter. This vulnerability could lead to unauthorized redirection and potential phishing attacks. Developers and administrators using affected versions of CakePHP should prioritize updating to the fixed versions to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string parameter. This issue is fixed in versions 2.11.1, 3.3.6, and 4.1.1.
Related CVEs
Other vulnerabilities affecting the same vendor(s)