VDB
Sign up
CRITICAL10.0

GHSA-27qr-636m-wxg2

codeigniter/framework SQL injection in ODBC database driver

Quick fix

GHSA-27qr-636m-wxg2 — codeigniter/framework: upgrade to the fixed version with the command below.

composer require codeigniter/framework:^3.1.0

Details

CodeIgniter 3.1.0 addressed a critical security issue within the ODBC database driver. This update includes crucial fixes to mitigate a SQL injection vulnerability, preventing potential exploitation by attackers. It is noteworthy that these fixes render the query builder and escape() functions incompatible with the ODBC driver. However, the update introduces actual query binding as a more secure alternative.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/codeigniter/framework
Introduced in: 0Fixed in: 3.1.0
Fixcomposer require codeigniter/framework:^3.1.0

References