First published: Fri Oct 07 2022(Updated: )
B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_in() function.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Codeigniter Codeigniter | >=3.0<=3.1.13 | |
Codeigniter Codeigniter | =3.0 | |
Codeigniter Codeigniter | =3.0-rc | |
Codeigniter Codeigniter | =3.0-rc2 | |
Codeigniter Codeigniter | =3.0-rc3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40833 is a SQL Injection vulnerability in B.C. Institute of Technology CodeIgniter <=3.1.13.
CVE-2022-40833 has a severity rating of 9.8 (critical).
CVE-2022-40833 affects B.C. Institute of Technology CodeIgniter <=3.1.13 by allowing SQL Injection through the system\database\DB_query_builder.php or_where_in() function.
Currently, there is no official fix available for CVE-2022-40833, but it is recommended to update to a fixed version once it becomes available.
You can find more information about CVE-2022-40833 at the following reference: [link](https://github.com/726232111/CodeIgniter3.1.13-SQL-Inject/blob/main/README.md)