Session Fixation Vulnerability in CodeIgniter Web Framework
CVE-2018-12071

9.8CRITICAL

Key Information:

Vendor
CVE Published:
17 June 2018

What is CVE-2018-12071?

A Session Fixation vulnerability has been identified in CodeIgniter, affecting versions prior to 3.1.9. This flaw occurs due to the improper handling of the session.use_strict_mode setting within the Session Library. Attackers can exploit this vulnerability to hijack sessions and gain unauthorized access to user accounts, highlighting the importance of secure session management in web applications. Developers using affected versions are strongly recommended to upgrade to ensure robust security against potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.