peter bassill · operator
$ cve CVE-2014-8684 JSON

CVE-2014-8684 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 71.7% (pctl 99)

Patch early

A public exploit exists.

Description

CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS71.71% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-310
On CISA KEVno
Public exploityes
Published2017-09-19
Last modified2026-06-17

Affected (2)

VendorProduct
codeignitercodeigniter
kohanaframeworkkohana

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD