MEDIUM4.7
GHSA-q9j3-4ghj-6h57
Inadequate XSS Prevention in CodeIgniter/Framework Security Library
Quick fix
GHSA-q9j3-4ghj-6h57 — codeigniter/framework: upgrade to the fixed version with the command below.
composer require codeigniter/framework:^3.0.3Details
The xss_clean() method in the Security Library of CodeIgniter/Framework, specifically in versions before 3.0.3, exhibited a vulnerability that allowed certain Cross-Site Scripting (XSS) vectors to bypass its intended protection mechanisms.
The xss_clean() method is designed to sanitize input data by removing potentially malicious content, thus preventing XSS attacks. However, in versions prior to 3.0.3, it was discovered that the method did not adequately mitigate specific XSS vectors, leaving a potential security gap.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/codeigniter/framework
Introduced in:
0Fixed in: 3.0.3Fix
composer require codeigniter/framework:^3.0.3References
- https://github.com/bcit-ci/CodeIgniter/commit/71b1b3f5b2dcc0f4b652e9494e9853b82541ac8c[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/codeigniter/framework/2015-10-31-1.yaml[WEB]
- https://github.com/bcit-ci/CodeIgniter[PACKAGE]
- https://www.codeigniter.com/user_guide/changelog.html#version-3-0-3[WEB]