First published: Wed Feb 21 2018(Updated: )
The xss_clean function in CodeIgniter before 2.1.4 might allow remote attackers to bypass an intended protection mechanism and conduct cross-site scripting (XSS) attacks via an unclosed HTML tag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Codeigniter Codeigniter | <2.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2013-4891.
The severity of CVE-2013-4891 is medium with a CVSS score of 6.1.
CVE-2013-4891 affects CodeIgniter versions before 2.1.4.
An attacker can exploit CVE-2013-4891 by bypassing the xss_clean function and conducting cross-site scripting (XSS) attacks using an unclosed HTML tag.
Yes, updating CodeIgniter to version 2.1.4 or later will fix CVE-2013-4891.