CyberRota Analysis
AI analysis pending.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
External Security References
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2014-8686
Severity
CRITICAL
CVSS
9.8
EPSS
37.22%
Original NVD Description
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.