CVE-2016-4793 | CakePHP up to 3.2.4 HTTP Header clientIp CLIENT-IP input validation (EDB-39813 / Nessus ID 97393)
A vulnerability, which was classified as critical, was found in CakePHP up to 3.2.4. This affects the function clientIp of the component HTTP Header Handler. The manipulation of the argument CLIENT-IP leads to improper input validation.
This vulnerability is uniquely identified as CVE-2016-4793. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.