Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q9j3-4ghj-6h57

Опубликовано: 15 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.7

Описание

Inadequate XSS Prevention in CodeIgniter/Framework Security Library

The xss_clean() method in the Security Library of CodeIgniter/Framework, specifically in versions before 3.0.3, exhibited a vulnerability that allowed certain Cross-Site Scripting (XSS) vectors to bypass its intended protection mechanisms.

The xss_clean() method is designed to sanitize input data by removing potentially malicious content, thus preventing XSS attacks. However, in versions prior to 3.0.3, it was discovered that the method did not adequately mitigate specific XSS vectors, leaving a potential security gap.

Пакеты

Наименование

codeigniter/framework

composer
Затронутые версииВерсия исправления

< 3.0.3

3.0.3

4.7 Medium

CVSS3

Дефекты

CWE-79

4.7 Medium

CVSS3

Дефекты

CWE-79