PT-2026-66683 · Codeigniter4 · Codeigniter4

CVE-2026-63223

·

Publicado

2026-07-31

·

Atualizado

2026-07-31

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is image and mime in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an application preserves the client filename and stores uploads in a web-accessible script-enabled directory. Applications are impacted when they validate uploads using is image or mime in without an independent safe extension check (such as ext in on patched versions), save uploaded files using the client-supplied filename, and place uploads in a web-accessible directory where PHP files can execute. This issue is fixed in version 4.7.4.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-63223

Produtos afetados

Codeigniter4