Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xjp4-6w75-qrj7

Опубликовано: 01 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.4

Описание

Remote CLI Command Execution Vulnerability in CodeIgniter4

Impact

This vulnerability allows attackers to execute CLI routes via HTTP request.

Patches

Upgrade to v4.1.9 or later.

Workarounds

None.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

codeigniter4/framework

composer
Затронутые версииВерсия исправления

< 4.1.9

4.1.9

EPSS

Процентиль: 61%
0.00413
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-20
CWE-94

Связанные уязвимости

CVSS3: 9.4
nvd
почти 4 года назад

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. There are currently no known workarounds for this vulnerability.

CVSS3: 9.4
debian
почти 4 года назад

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web fr ...

EPSS

Процентиль: 61%
0.00413
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-20
CWE-94