CVE-2022-40827 describes a critical SQL Injection vulnerability (CWE-89) affecting B.C. Institute of Technology CodeIgniter versions up to and including 3.1.13, specifically within the system\database\DB_query_builder.php where() function. This vulnerability carries a CVSS score of 9.8 (Critical), indicating it is network-exploitable with low attack complexity, requiring no privileges or user interaction, and can lead to complete compromise of confidentiality, integrity, and availability. While multiple third parties dispute its validity, there is no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing. Despite the lack of confirmed exploits, the vulnerability has garnered significant community discussion with 10 mentions, placing it in the top 1% of all CVEs for community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, <= 3.1.13CPE matchmatch criteria | cpe:2.3:a:codeigniter:codeigniter:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:codeigniter:codeigniter:3.0:-:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:codeigniter:codeigniter:3.0:rc:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:codeigniter:codeigniter:3.0:rc2:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:codeigniter:codeigniter:3.0:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.