First published: Tue Oct 15 2024(Updated: )
A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CodeIgniter |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41344 is a high-severity vulnerability that allows unauthorized password changes in CodeIgniter 3.1.13.
To fix CVE-2024-41344, upgrade to the latest version of CodeIgniter that addresses this CSRF vulnerability.
The potential impacts of CVE-2024-41344 include unauthorized access to the administrator account and privilege escalation.
CVE-2024-41344 affects users of CodeIgniter version 3.1.13 and earlier, particularly those with administrative interfaces.
CVE-2024-41344 allows attackers to perform Cross-Site Request Forgery (CSRF) attacks to change admin passwords.