icon

We found results for “

CVE-2022-35943

Date: August 12, 2022

Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow "SameSite Attackers" (https://canitakeyoursubdomain.name/) to bypass the "CodeIgniter4 CSRF protection" (https://codeigniter4.github.io/userguide/libraries/security.html) mechanism with CodeIgniter Shield. For this attack to succeed, the attacker must have direct (or indirect, e.g., XSS) control over a subdomain site (e.g., "https://a.example.com/";) of the target site (e.g., "http://example.com/";). Upgrade to CodeIgniter v4.2.3 or later and Shield v1.0.0-beta.2 or later. As a workaround: set "Config\Security::$csrfProtection" to "'session,'"remove old session data right after login (immediately after ID and password match) and regenerate CSRF token right after login (immediately after ID and password match)

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Cross-Site Request Forgery (CSRF)

CWE-352

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): HIGH
Availability (A): LOW

Do you need more information?

Contact Us