First published: Tue Sep 19 2017(Updated: )
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Codeigniter Codeigniter | <=2.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.