CVE-2025-45406
MEDIUMCodeIgniter4 v4.6.0 - Stored Cross-Site Scripting via Debugbar Time Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-45406. PoCs published by Pablo Santiago.
AI-analyzed exploit summary This exploit leverages broken access control in Laundry Booking Management System 1.0 to create an unauthenticated user and upload a PHP webshell, which is then used to execute a reverse shell payload via command injection.
Description
A stored cross-site scripting (XSS) vulnerability in CodeIgniter4 v4.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the debugbar_time parameter. NOTE: this is disputed by the Supplier because attackers cannot influence the value of debugbar_time, and because debugbar-related data is automatically escaped by the CodeIgniter Parser class.
Exploits (1)
This exploit leverages broken access control in Laundry Booking Management System 1.0 to create an unauthenticated user and upload a PHP webshell, which is then used to execute a reverse shell payload via command injection.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N