High severity8.6NVD Advisory· Published Dec 22, 2022· Updated Jun 17, 2026
CVE-2022-46170
CVE-2022-46170
Description
CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to DatabaseHandler, MemcachedHandler, or RedisHandler, then if an attacker gets one session cookie (e.g., one for user pages), they may be able to access pages that require another session cookie (e.g., for admin pages). This issue has been patched, please upgrade to version 4.2.11 or later. As a workaround, use only one session cookie.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
codeigniter4/frameworkPackagist | < 4.2.11 | 4.2.11 |
Affected products
4cpe:2.3:a:codeigniter:codeigniter:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:codeigniter:codeigniter:*:*:*:*:*:*:*:*range: >=4.0.0,<4.2.11
- (no CPE)range: < 4.2.11
- osv-coords2 versions
>= 4.0.0, < 4.2.11+ 1 more
- (no CPE)range: >= 4.0.0, < 4.2.11
- (no CPE)range: < 4.2.11
Patches
Vulnerability mechanics
References
6- github.com/codeigniter4/CodeIgniter4/commit/f9fb6574fbeb5a4aa63f7ea87296523e10db9328nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-6cq5-8cj7-g558ghsaADVISORY
- github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-6cq5-8cj7-g558nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-46170ghsaADVISORY
- codeigniter4.github.io/userguide/libraries/sessions.htmlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/codeigniter4/framework/CVE-2022-46170.yamlghsaWEB
News mentions
0No linked articles in our index yet.