Feed/CVE-2016-10131
CVE-2016-10131CRITICALCVSS 9.8

CodeIgniter arbitrary code execution

Published May 17, 2022·Updated Jul 6, 2026

NVD Description

system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from field to insert sendmail command-line arguments.

Affected Packages (1)

bcit-ci/codeigniterCOMPOSER
Fixed in 3.1.3

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free