Lack of data validation In codeigniter4/framework
Description
Remote CLI Command Execution Vulnerability in CodeIgniter4
Impact
This vulnerability allows attackers to execute CLI routes via HTTP request.
Patches
Upgrade to v4.1.9 or later.
Workarounds
None.
For more information
If you have any questions or comments about this advisory:
Open an issue in codeigniter4/CodeIgniter4
Email us at SECURITY.md
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 4.1.9 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.