PT-2024-24230 · Unknown · Ecommerce-Codeigniter-Bootstrap

Liotree

·

Published

2024-04-29

·

Updated

2025-09-23

·

CVE-2024-31822

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ecommerce-CodeIgniter-Bootstrap (affected versions not specified)
Description An issue in Ecommerce-CodeIgniter-Bootstrap allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component. This issue can lead to privilege escalation. It is recommended to review the code for validation gaps and limit file write destinations to prevent remote attacks.
Recommendations As a temporary workaround, consider disabling the saveLanguageFiles method of the Languages.php component until a patch is available. Restrict access to the Languages.php component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-31822

Affected Products

Ecommerce-Codeigniter-Bootstrap