Threats Tagged 'ghsa-hhmc-q9hp-r662'
View all threats tagged with 'ghsa-hhmc-q9hp-r662'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-hhmc-q9hp-r662'
Click on any threat for detailed analysis and mitigation recommendations
Framework: CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames (CVE-2026-63222)CVE-2026-63222 0 CodeIgniter versions prior to 4.7.4 have a path traversal vulnerability in the UploadedFile::move() method when called without a second argument. The method uses the client-provided filename without sanitization, allowing an attacker to supply filenames with path traversal sequences to write files outside the intended directory. The vulnerability is fixed in version 4.7.4 by sanitizing the default filename. Applications explicitly passing client filenames as the second argument remain responsible for sanitizing those names. Join the discussion | GCVE Database | 08/07/2026, 18:23:46 UTC Added: 08/08/2026, 14:52:24 UTC |
Showing 1 to 1 of 1 result