Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7528-7jg5-6g62

Опубликовано: 27 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Cross-site Scripting Vulnerability in CodeIgniter4

Impact

Cross-Site Scripting (XSS) vulnerability was found in API\ResponseTrait in Codeigniter4. Attackers can do XSS attacks if you are using API\ResponseTrait.

Patches

Upgrade to v4.1.8 or later.

Workarounds

Do one of the following:

  1. Do not use API\ResponseTrait nor ResourceController
  2. Disable Auto Route and Use Defined Routes Only

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

codeigniter4/framework

composer
Затронутые версииВерсия исправления

< 4.1.8

4.1.8

EPSS

Процентиль: 70%
0.00621
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A cross-site scripting (XSS) vulnerability was found in `API\ResponseTrait` in Codeigniter4 prior to version 4.1.8. Attackers can do XSS attacks if a potential victim is using `API\ResponseTrait`. Version 4.1.8 contains a patch for this vulnerability. There are two potential workarounds available. Users may avoid using `API\ResponseTrait` or `ResourceController` Users may also disable Auto Route and use defined routes only.

CVSS3: 5.4
debian
около 4 лет назад

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web fr ...

EPSS

Процентиль: 70%
0.00621
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79