CVE-2022-21715 MEDIUM

CVE-2022-21715: Cross-site Scripting Vulnerability in CodeIgniter4

Vendor Codeigniter4
Product CodeIgniter4
Weakness CWE-79 · XSS
Published January 24, 2022
Last update April 23, 2025

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

What the vulnerability does

Description

CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A cross-site scripting (XSS) vulnerability was found in `API\ResponseTrait` in Codeigniter4 prior to version 4.1.8. Attackers can do XSS attacks if a potential victim is using `API\ResponseTrait`. Version 4.1.8 contains a patch for this vulnerability. There are two potential workarounds available. Users may avoid using `API\ResponseTrait` or `ResourceController` Users may also disable Auto Route and use defined routes only.

Key dates

Disclosure timeline

January 24, 2022 CVE published
April 23, 2025 Record updated