CVE-2022-21647 is a critical deserialization of untrusted data vulnerability affecting CodeIgniter4, specifically within the old() function. This flaw allows remote attackers to inject arbitrary auto-loadable objects, potentially leading to the execution of existing PHP code on the server and known SQL injection exploits. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While a working exploit is known, there is no public exploit code available in Metasploit or ExploitDB, and it currently lacks significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.1.6CPE matchmatch criteria | cpe:2.3:a:codeigniter:codeigniter:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.