CVE-2022-35943 is a high-severity vulnerability affecting CodeIgniter Shield, an authentication and authorization framework for CodeIgniter 4. It allows SameSite attackers to bypass CodeIgniter4's Cross-Site Request Forgery (CSRF) protection mechanism. The attack requires the attacker to control a subdomain of the target site. With a CVSS score of 8.8, this vulnerability has a high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2.3CPE matchmatch criteria | cpe:2.3:a:codeigniter:codeigniter:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:codeigniter:shield:1.0.0:beta:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.