VYPR
Critical severity9.8NVD Advisory· Published Jan 12, 2017· Updated May 6, 2026

CVE-2016-10131

CVE-2016-10131

Description

system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from field to insert sendmail command-line arguments.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
bcit-ci/codeigniterPackagist
< 3.1.33.1.3

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.