First published: Sat Feb 26 2022(Updated: )
CVE-2022-24712: Cross-Site Request Forgery (CSRF) Protection Bypass Vulnerability in CodeIgniter4
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/codeigniter4/framework | <4.1.9 | |
Codeigniter Codeigniter | >=4.0.0<4.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24712 is a Cross-Site Request Forgery (CSRF) Protection Bypass Vulnerability in CodeIgniter4.
CVE-2022-24712 affects versions prior to 4.1.9 of CodeIgniter4.
Remote attackers can exploit CVE-2022-24712 to bypass the CodeIgniter4 Cross-Site Request Forgery (CSRF) protection mechanism.
CVE-2022-24712 has a severity score of 8.8 (High).
To fix CVE-2022-24712, users should upgrade to version 4.1.9 of CodeIgniter4.