CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-model validation are also vulnerable because they use the Validation library internally. This issue is patched in version 4.3.5.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2023-1576 | CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-model validation are also vulnerable because they use the Validation library internally. This issue is patched in version 4.3.5. |
![]() |
GHSA-m6m8-6gq8-c9fj | Remote Code Execution Vulnerability in Validation Placeholders in CodeIgniter4 |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 10 Jan 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-10T20:38:42.898Z
Reserved: 2023-05-11T16:33:45.733Z
Link: CVE-2023-32692

Updated: 2024-08-02T15:25:36.360Z

Status : Modified
Published: 2023-05-30T04:15:10.097
Modified: 2024-11-21T08:03:51.783
Link: CVE-2023-32692

No data.

No data.