The xss_clean function in CodeIgniter before 2.1.4 might allow remote attackers to bypass an intended protection mechanism and conduct cross-site scripting (XSS) attacks via an unclosed HTML tag.
References
Link | Resource |
---|---|
https://www.codeigniter.com/userguide2/changelog.html | Release Notes |
https://nealpoole.com/blog/2013/07/codeigniter-21-xss-clean-filter-bypass/ | Exploit Third Party Advisory |
https://github.com/bcit-ci/CodeIgniter/issues/4020 | Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2018-02-21 08:29
Updated : 2018-03-09 10:07
NVD link : CVE-2013-4891
Mitre link : CVE-2013-4891
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
codeigniter
- codeigniter