QID 996026

Date Published: 2023-11-27

QID 996026: PHP (Composer) Security Update for codeigniter4/shield (GHSA-j72f-h752-mx4w)

If successful login attempts are recorded, the raw tokens are stored in the log table. If a malicious person somehow views the data in the log table, he or she can obtain a raw token, which can then be used to send a request with that user's authority.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-j72f-h752-mx4w for updates and patch information.
    Vendor References

    CVEs related to QID 996026

    Software Advisories
    Advisory ID Software Component Link
    GHSA-j72f-h752-mx4w codeigniter4/shield URL Logo github.com/advisories/GHSA-j72f-h752-mx4w