B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.
References
Link | Resource |
---|---|
https://github.com/726232111/CodeIgniter3.1.13-SQL-Inject/blob/main/README.md | Exploit Third Party Advisory |
https://github.com/bcit-ci/CodeIgniter/issues/6161 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-07T00:00:00
Updated: 2024-05-17T20:26:23.088093
Reserved: 2022-09-19T00:00:00
Link: CVE-2022-40825
JSON object: View
NVD Information
Status : Modified
Published: 2022-10-07T11:15:10.983
Modified: 2024-05-17T21:15:06.997
Link: CVE-2022-40825
JSON object: View
Redhat Information
No data.
CWE