CRITICAL9.8
GHSA-2pcj-76hj-xqhm
CodeIgniter arbitrary code execution
Quick fix
GHSA-2pcj-76hj-xqhm — bcit-ci/codeigniter: upgrade to the fixed version with the command below.
composer require bcit-ci/codeigniter:^3.1.3Details
system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from field to insert sendmail command-line arguments.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/bcit-ci/codeigniter
Introduced in:
0Fixed in: 3.1.3Fix
composer require bcit-ci/codeigniter:^3.1.3References
- https://nvd.nist.gov/vuln/detail/CVE-2016-10131[ADVISORY]
- https://github.com/bcit-ci/CodeIgniter/issues/4844[WEB]
- https://github.com/bcit-ci/CodeIgniter/issues/4963[WEB]
- https://github.com/bcit-ci/CodeIgniter/commit/8db01f13809a92bac7bc95b02893175d7654d627[WEB]
- https://github.com/codeigniter4/framework[PACKAGE]
- https://www.codeigniter.com/userguide3/changelog.html#bug-fixes-for-3-1-3[WEB]
- http://www.securityfocus.com/bid/96851[WEB]