Логотип exploitDog
bind:CVE-2022-46170
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-46170

Количество 3

Количество 3

nvd логотип

CVE-2022-46170

около 3 лет назад

CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to `DatabaseHandler`, `MemcachedHandler`, or `RedisHandler`, then if an attacker gets one session cookie (e.g., one for user pages), they may be able to access pages that require another session cookie (e.g., for admin pages). This issue has been patched, please upgrade to version 4.2.11 or later. As a workaround, use only one session cookie.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2022-46170

около 3 лет назад

CodeIgniter is a PHP full-stack web framework. When an application use ...

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-6cq5-8cj7-g558

около 3 лет назад

CodeIgniter4 Potential Session Handlers Vulnerability

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-46170

CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to `DatabaseHandler`, `MemcachedHandler`, or `RedisHandler`, then if an attacker gets one session cookie (e.g., one for user pages), they may be able to access pages that require another session cookie (e.g., for admin pages). This issue has been patched, please upgrade to version 4.2.11 or later. As a workaround, use only one session cookie.

CVSS3: 8.6
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-46170

CodeIgniter is a PHP full-stack web framework. When an application use ...

CVSS3: 8.6
0%
Низкий
около 3 лет назад
github логотип
GHSA-6cq5-8cj7-g558

CodeIgniter4 Potential Session Handlers Vulnerability

CVSS3: 8.6
0%
Низкий
около 3 лет назад

Уязвимостей на страницу