Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1xOWozLTRnaGotNmg1N84AA8GQ
Inadequate XSS Prevention in CodeIgniter/Framework Security Library
The xss_clean() method in the Security Library of CodeIgniter/Framework, specifically in versions before 3.0.3, exhibited a vulnerability that allowed certain Cross-Site Scripting (XSS) vectors to bypass its intended protection mechanisms.
The xss_clean() method is designed to sanitize input data by removing potentially malicious content, thus preventing XSS attacks. However, in versions prior to 3.0.3, it was discovered that the method did not adequately mitigate specific XSS vectors, leaving a potential security gap.
Permalink: https://github.com/advisories/GHSA-q9j3-4ghj-6h57JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xOWozLTRnaGotNmg1N84AA8GQ
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 7 months ago
Updated: 7 months ago
CVSS Score: 4.7
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Identifiers: GHSA-q9j3-4ghj-6h57
References:
- https://github.com/bcit-ci/CodeIgniter/commit/71b1b3f5b2dcc0f4b652e9494e9853b82541ac8c
- https://github.com/FriendsOfPHP/security-advisories/blob/master/codeigniter/framework/2015-10-31-1.yaml
- https://www.codeigniter.com/user_guide/changelog.html#version-3-0-3
- https://github.com/advisories/GHSA-q9j3-4ghj-6h57
Blast Radius: 12.7
Affected Packages
packagist:codeigniter/framework
Dependent packages: 69Dependent repositories: 509
Downloads: 1,838,219 total
Affected Version Ranges: < 3.0.3
Fixed in: 3.0.3
All affected versions: 3.0.0, 3.0.1, 3.0.2
All unaffected versions: 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.1.0, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5, 3.1.6, 3.1.7, 3.1.8, 3.1.9, 3.1.10, 3.1.11, 3.1.12, 3.1.13