Описание
(CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling ...)
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps/noble | needs-triage | |
| esm-apps/resolute | needs-triage | |
| jammy | DNE | |
| noble | needs-triage | |
| resolute | needs-triage | |
| upstream | needs-triage |
Показывать по
10
Ссылки на источники
EPSS
Процентиль: 37%
0.0045
Низкий
7.5 High
CVSS3
Связанные уязвимости
CVSS3: 7.5
nvd
6 дней назад
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploaded content outside the intended directory when the application exposes an upload path. This issue is fixed in version 4.7.4.
CVSS3: 7.5
debian
6 дней назад
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling ...
EPSS
Процентиль: 37%
0.0045
Низкий
7.5 High
CVSS3