VYPR

Bitnami package

codeigniter

pkg:bitnami/codeigniter

Vulnerabilities (23)

  • CVE-2023-46240Oct 31, 2023
    affected < 4.4.3fixed 4.4.3

    CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displayed even if in the production environment. As a result, confidential information may be leaked. Version 4.4.3 contains a patch. As

  • CVE-2023-32692May 30, 2023
    affected < 4.3.5fixed 4.3.5

    CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-model validation are also vulnera

  • CVE-2022-46170Dec 22, 2022
    affected >= 4.0.0, < 4.2.11fixed 4.2.11

    CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user pages and one for admin pages) and (2) a session handler is set to `DatabaseHandler`, `MemcachedHandler`, or `RedisHandler`, then if an attacker gets one sess

  • CVE-2022-23556Dec 22, 2022
    affected >= 4.0.0, < 4.2.11fixed 4.2.11

    CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the server is behind a reverse proxy. This issue has been patched, please upgrade to version 4.2.11 or later, and configure `Config\App::$proxyIPs`. As a workaroun

  • CVE-2022-40835Oct 7, 2022
    affected >= 3.0.0, < 3.1.13fixed 3.1.13

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php. Note: Multiple third parties have disputed this as not a valid vulnerability

  • CVE-2022-40834Oct 7, 2022
    affected >= 3.0.0, < 3.1.13fixed 3.1.13

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_not_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40833Oct 7, 2022
    affected >= 3.0.0, < 3.1.13fixed 3.1.13

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40832Oct 7, 2022
    affected >= 3.0.0, < 3.1.13fixed 3.1.13

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php having() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40831Oct 7, 2022
    affected >= 3.0.0, < 3.1.13fixed 3.1.13

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40830Oct 7, 2022
    affected >= 3.0.0, < 3.1.13fixed 3.1.13

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40829Oct 7, 2022
    affected >= 3.0.0, < 3.1.13fixed 3.1.13

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40828Oct 7, 2022
    affected >= 3.0.0, < 3.1.13fixed 3.1.13

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40827Oct 7, 2022
    affected >= 3.0.0, < 3.1.13fixed 3.1.13

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40826Oct 7, 2022
    affected >= 3.0.0, < 3.1.13fixed 3.1.13

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_having() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40825Oct 7, 2022
    affected >= 3.0.0, < 3.1.13fixed 3.1.13

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40824Oct 7, 2022
    affected >= 3.0.0, < 3.1.13fixed 3.1.13

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-39284Oct 6, 2022
    affected >= 4.0.0, < 4.2.7fixed 4.2.7

    CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `true` in `Config\Cookie` is not reflected in `set_cookie()` or `Response::setCookie()`. As a result cookie values are erroneously exposed to scripts. It should be

  • CVE-2022-35943Aug 12, 2022
    affected < 4.2.3fixed 4.2.3

    Shield is an authentication and authorization framework for CodeIgniter 4. This vulnerability may allow [SameSite Attackers](https://canitakeyoursubdomain.name/) to bypass the [CodeIgniter4 CSRF protection](https://codeigniter4.github.io/userguide/libraries/security.html) mechani

  • CVE-2022-24712Feb 28, 2022
    affected >= 4.0.0, < 4.1.9fixed 4.1.9

    CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1.9 might allow remote attackers to bypass the CodeIgniter4 Cross-Site Request Forgery (CSRF) protection mechanism. Users should upgrade to version 4.1.9. There a

  • CVE-2022-24711Feb 28, 2022
    affected >= 4.0.0, < 4.1.9fixed 4.1.9

    CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. There are currently no known workarounds for

Page 1 of 2