PT-2020-12327 · Ellislab · Codeigniter

Published

2020-03-23

·

Updated

2024-03-06

·

CVE-2020-10793

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CodeIgniter versions through 4.0.0
Description The issue allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. However, it is argued by a contributor to the CodeIgniter framework that the issue should not be attributed to CodeIgniter itself, as the framework does not provide login or user management facilities beyond a Session library. Instead, the issue is reportedly with a custom module or plugin to CodeIgniter.
Recommendations For CodeIgniter versions through 4.0.0, consider disabling or restricting access to the custom module or plugin that introduces the issue until a fix is available. Additionally, review and secure any custom login or user management implementations to prevent exploitation.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BIT-CODEIGNITER-2020-10793
CVE-2020-10793
GHSA-JWQP-WH5G-4GMM

Affected Products

Codeigniter