PT-2020-12327 · Ellislab · Codeigniter
Published
2020-03-23
·
Updated
2024-03-06
·
CVE-2020-10793
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CodeIgniter versions through 4.0.0
Description
The issue allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. However, it is argued by a contributor to the CodeIgniter framework that the issue should not be attributed to CodeIgniter itself, as the framework does not provide login or user management facilities beyond a Session library. Instead, the issue is reportedly with a custom module or plugin to CodeIgniter.
Recommendations
For CodeIgniter versions through 4.0.0, consider disabling or restricting access to the custom module or plugin that introduces the issue until a fix is available. Additionally, review and secure any custom login or user management implementations to prevent exploitation.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codeigniter