PT-2020-12327 · Ellislab · Codeigniter

CVE-2020-10793

·

Published

2020-03-23

·

Updated

2024-03-06

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CodeIgniter versions through 4.0.0
Description The issue allows remote attackers to gain privileges via a modified Email ID to the "Select Role of the User" page. However, it is argued by a contributor to the CodeIgniter framework that the issue should not be attributed to CodeIgniter itself, as the framework does not provide login or user management facilities beyond a Session library. Instead, the issue is reportedly with a custom module or plugin to CodeIgniter.
Recommendations For CodeIgniter versions through 4.0.0, consider disabling or restricting access to the custom module or plugin that introduces the issue until a fix is available. Additionally, review and secure any custom login or user management implementations to prevent exploitation.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-CODEIGNITER-2020-10793
CVE-2020-10793
GHSA-JWQP-WH5G-4GMM

Affected Products

Codeigniter