CVE-2016-4793
HIGHCakePHP < 3.2.4 - IP Spoofing via CLIENT-IP HTTP Header
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-4793. PoCs published by Dawid Golunski.
AI-analyzed exploit summary The exploit demonstrates IP spoofing in CakePHP Framework by manipulating the CLIENT-IP header, leading to potential ACL bypass or injection vulnerabilities. It includes a proof-of-concept for both CakePHP and Croogo CMS.
Description
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
Exploits (1)
exploitdb
WORKING POC
by Dawid Golunski · textwebappsphp
https://www.exploit-db.com/exploits/39813
The exploit demonstrates IP spoofing in CakePHP Framework by manipulating the CLIENT-IP header, leading to potential ACL bypass or injection vulnerabilities. It includes a proof-of-concept for both CakePHP and Croogo CMS.
Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:
CakePHP Framework <= 3.2.4, 3.1.11, 2.8.1, 2.7.10, 2.6.12
No auth needed
Prerequisites:
Vulnerable version of CakePHP Framework · Ability to send HTTP requests with custom headers
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (5)
Core 5
Core References
Vendor Advisory x_refsource_confirm
https://support.citrix.com/article/CTX236992
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/39813/
Exploit, Third Party Advisory x_refsource_misc
http://legalhackers.com/advisories/CakePHP-IP-Spoofing-Vulnerability.txt
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/95846
Patch, Vendor Advisory x_refsource_confirm
https://bakery.cakephp.org/2016/03/13/cakephp_2613_2711_282_3017_3112_325_released.html
Scores
CVSS v3
7.5
EPSS
0.0828
EPSS Percentile
92.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-20
Status
published
Products (2)
cakephp/cakephp
< 3.2.4
cakephp/cakephp
1.2.0 - 2.6.13Packagist
Published
Jan 23, 2017
Tracked Since
Feb 18, 2026