Lucene search

K

Shield Security Vulnerabilities

cve
cve

CVE-2022-35943

Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow SameSite Attackers to bypass the CodeIgniter4 CSRF protection mechanism with CodeIgniter Shield. For this attack to succeed, the attacker must have direct (or indirect, e.g., XSS) control over a ...

8.8CVSS

8.8AI Score

0.002EPSS

2022-08-12 09:15 PM
61
2
cve
cve

CVE-2023-27580

CodeIgniter Shield provides authentication and authorization for the CodeIgniter 4 PHP framework. An improper implementation was found in the password storage process. All hashed passwords stored in Shield v1.0.0-beta.3 or earlier are easier to crack than expected due to the vulnerability. Therefor...

7.5CVSS

5.9AI Score

0.001EPSS

2023-03-13 06:15 PM
23
cve
cve

CVE-2023-48707

CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The secretKey value is an important key for HMAC SHA256 authentication and in affected versions was stored in the database in cleartext form. If a malicious person somehow had access to the data in the database, t...

6.5CVSS

6.4AI Score

0.0005EPSS

2023-11-24 06:15 PM
16
cve
cve

CVE-2023-48708

CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded with the raw tokens stored in the log table. If a malicious person somehow views the data in the log table they can obtain a raw token which can then be ...

6.5CVSS

6.4AI Score

0.001EPSS

2023-11-24 06:15 PM
14