codeigniter4 CodeIgniter4是codeigniter4组织开源的一款轻量级Web开发框架。 CodeIgniter4 4.7.4之前版本存在信任管理问题漏洞,该漏洞源于IncomingRequest::isSecure()信任来自任意请求的X-Forwarded-Proto和Front-End-Https标头,可能导致攻击者伪造这些标头,导致应用错误地将HTTP请求视为安全。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| codeigniter4 | CodeIgniter4 | < 4.7.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| codeigniter4 | CodeIgniter4 | < 4.7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63223 | 9.8 CRITICAL | CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules |
| CVE-2026-63221 | 9.4 CRITICAL | CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with wher |
| CVE-2026-63222 | 7.5 HIGH | CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames |
No comments yet