CVE-2014-8684: Codeigniter
Critical severity, CVSS 9.8. EPSS: 71.7% chance of exploitation in the next 30 days.
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.
Affected products
- Codeigniter Codeigniter: up to and including 2.2.6
- Kohanaframework Kohana: version 3.2.3 only; version 3.3.0 only; version 3.3.1 only
Published 2017-09-19. Last modified 2026-06-17.