CVE-2025-24013

CVSS 3.1 Score 5.3 of 10 (medium)

Attack Complexity low
Integrity low
Confidentiality none
Availability none
Scope unchanged
Privileges Required none

Details

Published Jan 20, 2025
CWE ID 436

Summary

CVE-2025-24013 is a vulnerability affecting the CodeIgniter PHP web framework. Prior to version 4.5.8, CodeIgniter failed to validate headers properly in its name and value fields. An attacker could construct malformed headers using the Header class, which could disrupt application functionality. In extreme cases, these malformed requests might cause a Denial of Service (DoS) scenario if a web application firewall interprets them as malicious and blocks further communication with the application. CodeIgniter has addressed this issue in version 4.5.8 by implementing proper header validation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share