Critical severity9.8NVD Advisory· Published May 30, 2023· Updated Jun 17, 2026
CVE-2023-32692
CVE-2023-32692
Description
CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-model validation are also vulnerable because they use the Validation library internally. This issue is patched in version 4.3.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
codeigniter4/frameworkPackagist | < 4.3.5 | 4.3.5 |
Affected products
4cpe:2.3:a:codeigniter:codeigniter:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:codeigniter:codeigniter:*:*:*:*:*:*:*:*range: <4.3.5
- (no CPE)range: < 4.3.5
- osv-coords2 versions
< 4.3.5+ 1 more
- (no CPE)range: < 4.3.5
- (no CPE)range: < 4.3.5
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-m6m8-6gq8-c9fjghsaADVISORY
- github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-m6m8-6gq8-c9fjnvdMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-32692ghsaADVISORY
- github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.mdnvdRelease NotesWEB
- github.com/codeigniter4/CodeIgniter4/blob/develop/CHANGELOG.mdghsaWEB
- github.com/codeigniter4/CodeIgniter4/commit/6af677177fa1d9ad62f7a793bc96cba3068632baghsaWEB
News mentions
0No linked articles in our index yet.