PT-2022-15060 · Unknown · Codeigniter4

Kenjis

+1

·

Published

2022-01-24

·

Updated

2024-03-06

·

CVE-2022-21715

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CodeIgniter4 versions prior to 4.1.8
Description A cross-site scripting (XSS) issue was found in APIResponseTrait in CodeIgniter4. Attackers can perform XSS attacks if a potential victim is using APIResponseTrait.
Recommendations For versions prior to 4.1.8, upgrade to version 4.1.8 or later. As a temporary workaround, consider avoiding the use of APIResponseTrait or ResourceController. Alternatively, disable Auto Route and use defined routes only.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-CODEIGNITER-2022-21715
CVE-2022-21715
GHSA-7528-7JG5-6G62

Affected Products

Codeigniter4