CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-model validation are also vulnerable because they use the Validation library internally. This issue is patched in version 4.3.5.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1576 | CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-model validation are also vulnerable because they use the Validation library internally. This issue is patched in version 4.3.5. |
Github GHSA |
GHSA-m6m8-6gq8-c9fj | Remote Code Execution Vulnerability in Validation Placeholders in CodeIgniter4 |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 10 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-10T20:38:42.898Z
Reserved: 2023-05-11T16:33:45.733Z
Link: CVE-2023-32692
Updated: 2024-08-02T15:25:36.360Z
Status : Modified
Published: 2023-05-30T04:15:10.097
Modified: 2024-11-21T08:03:51.783
Link: CVE-2023-32692
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA