GHSA-q9j3-4ghj-6h57

Suggest an improvement
Source
https://github.com/advisories/GHSA-q9j3-4ghj-6h57
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-q9j3-4ghj-6h57/GHSA-q9j3-4ghj-6h57.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q9j3-4ghj-6h57
Published
2024-05-15T18:08:27Z
Modified
2024-11-29T05:41:14.070425Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N CVSS Calculator
Summary
Inadequate XSS Prevention in CodeIgniter/Framework Security Library
Details

The xss_clean() method in the Security Library of CodeIgniter/Framework, specifically in versions before 3.0.3, exhibited a vulnerability that allowed certain Cross-Site Scripting (XSS) vectors to bypass its intended protection mechanisms.

The xss_clean() method is designed to sanitize input data by removing potentially malicious content, thus preventing XSS attacks. However, in versions prior to 3.0.3, it was discovered that the method did not adequately mitigate specific XSS vectors, leaving a potential security gap.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-15T18:08:27Z"
}
References

Affected packages

Packagist / codeigniter/framework

Package

Name
codeigniter/framework
Purl
pkg:composer/codeigniter/framework

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.3

Affected versions

3.*

3.0rc
3.0rc2
3.0rc3
3.0.0
3.0.1rc
3.0.1rc2
3.0.1
3.0.2