Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-21715

Опубликовано: 24 янв. 2022
Источник: nvd
CVSS3: 5.4
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A cross-site scripting (XSS) vulnerability was found in API\ResponseTrait in Codeigniter4 prior to version 4.1.8. Attackers can do XSS attacks if a potential victim is using API\ResponseTrait. Version 4.1.8 contains a patch for this vulnerability. There are two potential workarounds available. Users may avoid using API\ResponseTrait or ResourceController Users may also disable Auto Route and use defined routes only.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:codeigniter:codeigniter:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.1.8 (исключая)

EPSS

Процентиль: 70%
0.00621
Низкий

5.4 Medium

CVSS3

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 5.4
debian
около 4 лет назад

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web fr ...

CVSS3: 5.4
github
около 4 лет назад

Cross-site Scripting Vulnerability in CodeIgniter4

EPSS

Процентиль: 70%
0.00621
Низкий

5.4 Medium

CVSS3

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79
CWE-79