CVE-2015-5725

CRITICAL

CodeIgniter < 2.2.4 - SQL Injection via Active Record Offset Method

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the offset method in the Active Record class in CodeIgniter before 2.2.4 allows remote attackers to execute arbitrary SQL commands via vectors involving the offset variable.

References (4)

Core 4

Scores

CVSS v3 9.8
EPSS 0.0240
EPSS Percentile 81.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
codeigniter/codeigniter < 2.2.4
Published Feb 21, 2018
Tracked Since Feb 18, 2026