CVE-2022-40828
- EPSS 0.93%
- Veröffentlicht 07.10.2022 11:15:11
- Zuletzt bearbeitet 09.04.2025 19:15:44
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
CVE-2022-40827
- EPSS 0.89%
- Veröffentlicht 07.10.2022 11:15:11
- Zuletzt bearbeitet 09.04.2025 19:15:44
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
CVE-2022-40825
- EPSS 0.93%
- Veröffentlicht 07.10.2022 11:15:10
- Zuletzt bearbeitet 21.11.2024 07:22:05
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
CVE-2022-40824
- EPSS 0.93%
- Veröffentlicht 07.10.2022 11:15:10
- Zuletzt bearbeitet 21.11.2024 07:22:05
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
CVE-2022-39284
- EPSS 0.88%
- Veröffentlicht 06.10.2022 20:15:35
- Zuletzt bearbeitet 21.11.2024 07:17:57
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or `Response::setCookie()`. As a result cookie values are erroneously exp...
CVE-2022-35943
- EPSS 0.58%
- Veröffentlicht 12.08.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 07:12:01
Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubdomain.name/) to bypass the [CodeIgniter4 CSRF protection](https://codeigniter4.github.io/userguide/li...
CVE-2022-24712
- EPSS 0.57%
- Veröffentlicht 28.02.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:55
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1.9 might allow remote attackers to bypass the CodeIgniter4 Cross-Site Request Forgery (CSRF) protection mechanism. Users should upg...
CVE-2022-24711
- EPSS 1.17%
- Veröffentlicht 28.02.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:50:55
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. There are curre...
CVE-2022-21715
- EPSS 1%
- Veröffentlicht 24.01.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:45:17
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A cross-site scripting (XSS) vulnerability was found in `API\ResponseTrait` in Codeigniter4 prior to version 4.1.8. Attackers can do XSS attacks if a potential victim is u...
CVE-2022-21647
- EPSS 37.67%
- Veröffentlicht 04.01.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:45:08
CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remote attackers may inject auto-loadable arbitrary objects with this vulnerability, and possibly execute...