PT-2022-16821 · Unknown · Codeigniter4

Mgatner

·

Published

2022-02-28

·

Updated

2024-03-06

·

CVE-2022-24711

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions CodeIgniter4 versions prior to 4.1.9
Description The issue allows attackers to execute CLI routes via HTTP request due to improper input validation. There are currently no known workarounds for this issue.
Recommendations Upgrade to version 4.1.9 or later to resolve the issue.

Exploit

Fix

Code Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-CODEIGNITER-2022-24711
CVE-2022-24711
GHSA-XJP4-6W75-QRJ7

Affected Products

Codeigniter4