← Volver al buscador de CVEs

CVE-2026-63222

CodeIgniter

Descripción

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploaded content outside the intended directory when the application exposes an upload path. This issue is fixed in version 4.7.4.

CVSS 7.5EPSS 0.44999999999999996%Riesgo 0.78
Ver fuente
Publicación
2026-07-31 06:16:31
Versiones afectadas
<4.7.4
Tipo
Aplicación web
Última modificación
2026-07-31 16:17:08
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N