VDB
KO
HIGH 7.5

GHSA-hhmc-q9hp-r662

CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames

Quick fix

GHSA-hhmc-q9hp-r662 — codeigniter4/framework: upgrade to the fixed version with the command below.

composer require codeigniter4/framework:^4.7.4

Details

### Impact In affected versions, calling `UploadedFile::move()` **without a second argument** uses the client-provided filename without sanitization. Depending on the destination path and server configuration, an attacker can supply a filename containing path traversal sequences (e.g. `../../public/shell.php`) to write uploaded content outside the intended upload directory.

The patch sanitizes this default (no-argument) path.

**Note:** The patch only sanitizes the filename when no second argument is passed. If your application **explicitly** passes a client-provided name as the second argument, you remain responsible for sanitizing it - the patch does not (and cannot) sanitize a caller-supplied filename: ```php // Unsafe - even after upgrading: $file->move(WRITEPATH . 'uploads', $file->getName()); $file->move(WRITEPATH . 'uploads', $file->getClientName()); ```

### Patches Upgrade to v4.7.4 or later.

### Workarounds If you cannot upgrade immediately, use a generated filename or sanitize the client filename before passing it to `move()`.

Use a generated filename: ```php $file->move(WRITEPATH . 'uploads', $file->getRandomName()); ``` Or sanitize the client filename before passing it to `move()`: ```php helper('security');

$name = sanitize_filename($file->getClientName()); $file->move(WRITEPATH . 'uploads', $name); ```

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist / codeigniter4/framework
Introduced in: 0 Fixed in: 4.7.4
Fix composer require codeigniter4/framework:^4.7.4

References