CVE-2023-32692

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
30/05/2023
Last modified:
06/06/2023

Description

CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-model validation are also vulnerable because they use the Validation library internally. This issue is patched in version 4.3.5.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:codeigniter:codeigniter:*:*:*:*:*:*:*:* 4.3.5 (excluding)