Description
CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-model validation are also vulnerable because they use the Validation library internally. This issue is patched in version 4.3.5.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1576 | CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-model validation are also vulnerable because they use the Validation library internally. This issue is patched in version 4.3.5. |
Github GHSA |
GHSA-m6m8-6gq8-c9fj | Remote Code Execution Vulnerability in Validation Placeholders in CodeIgniter4 |
References
History
Fri, 10 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-10T20:38:42.898Z
Reserved: 2023-05-11T16:33:45.733Z
Link: CVE-2023-32692
Updated: 2024-08-02T15:25:36.360Z
Status : Modified
Published: 2023-05-30T04:15:10.097
Modified: 2024-11-21T08:03:51.783
Link: CVE-2023-32692
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA