Remote CLI Command Execution Vulnerability in CodeIgniter4
Critical severity
GitHub Reviewed
Published
Feb 26, 2022
in
codeigniter4/CodeIgniter4
•
Updated Jan 24, 2024
Description
Published by the National Vulnerability Database
Feb 28, 2022
Published to the GitHub Advisory Database
Mar 1, 2022
Reviewed
Mar 1, 2022
Last updated
Jan 24, 2024
Impact
This vulnerability allows attackers to execute CLI routes via HTTP request.
Patches
Upgrade to v4.1.9 or later.
Workarounds
None.
For more information
If you have any questions or comments about this advisory:
References