CodeIgniter Vulnerability Enables Arbitrary Code Execution (CVSS 9.8)
ID: a8032366-66aa-5e43-ada3-0cc3283286fb
STIX ID: report--a8032366-66aa-5e43-ada3-0cc3283286fb
Feed Name: securityonline.info
**Executive summary:** A critical CodeIgniter vulnerability (CVE-2026-48062, CVSS 9.8) in the framework's file upload validation ('ext_in') can allow attackers to upload a web shell and achieve arbitrary code execution when applications accept user uploads and save files under their original names in a public folder; maintainers fixed the issue in CodeIgniter v4.7.3 and the report recommends immediate patching and additional hardening (store uploads outside the web root, use getRandomName(), disable script execution in upload folders, and verify extensions).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
