VDB
KO
CRITICAL 9.8

GHSA-mmj4-63m4-r6h5

CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules

Quick fix

GHSA-mmj4-63m4-r6h5 — codeigniter4/framework: upgrade to the fixed version with the command below.

composer require codeigniter4/framework:^4.7.4

Details

### Impact This is an unsafe file upload validation vulnerability that can lead to remote code execution in vulnerable application configurations.

Applications are impacted when they: - validate uploads using `is_image` or `mime_in` without an independent safe extension check, such as `ext_in` on patched versions - save uploaded files using the client-supplied filename - place uploads in a web-accessible directory where PHP files can execute

### Patches Upgrade to v4.7.4 or later.

### Workarounds - Save uploads outside the public web root, preferably under `writable/uploads`. - Use `$file->store()` or `$file->move($path, $file->getRandomName())` instead of preserving the original client filename. - Disable script execution in any public upload directory. - Manually verify the client filename extension before moving the file. - For image uploads, reject files when `$file->getClientExtension()` is not an allowed image extension. - For exact MIME-type validation, reject files when `$file->getClientExtension()` does not match `$file->guessExtension()`.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist / codeigniter4/framework
Introduced in: 0 Fixed in: 4.7.4
Fix composer require codeigniter4/framework:^4.7.4

References