PT-2018-10988 · Ellislab · Codeigniter

Published

2018-06-17

·

Updated

2025-06-09

·

CVE-2018-12071

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CodeIgniter versions prior to 3.1.9
Description A Session Fixation issue exists because session.use strict mode in the Session Library was mishandled. This issue can be exploited due to the mishandling of the session configuration.
Recommendations For versions prior to 3.1.9, update to version 3.1.9 or later to resolve the issue. As a temporary workaround, consider setting session.use strict mode to TRUE in the Session Library configuration to minimize the risk of exploitation.

Fix

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2018-12071
GHSA-G434-3Q2J-HJ4R

Affected Products

Codeigniter