Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-49jm-g4m8-x53p

Опубликовано: 25 июл. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Withdrawn Advisory: CodeIgniter4 Cross-Site Scripting Vulnerability in debugbar_time Parameter

Withdrawn Advisory

This advisory has been withdrawn because the original report was found to be invalid. This link is maintained to preserve external references. For more information, see https://github.com/github/advisory-database/pull/5862.

Original Description

A stored cross-site scripting (XSS) vulnerability in CodeIgniter4 v4.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the debugbar_time parameter.

Пакеты

Наименование

codeigniter4/framework

composer
Затронутые версииВерсия исправления

<= 4.6.2

Отсутствует

EPSS

Процентиль: 7%
0.00028
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
7 месяцев назад

A stored cross-site scripting (XSS) vulnerability in CodeIgniter4 v4.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the debugbar_time parameter. NOTE: this is disputed by the Supplier because attackers cannot influence the value of debugbar_time, and because debugbar-related data is automatically escaped by the CodeIgniter Parser class.

CVSS3: 6.1
debian
7 месяцев назад

A stored cross-site scripting (XSS) vulnerability in CodeIgniter4 v4.6 ...

EPSS

Процентиль: 7%
0.00028
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79