Remote Execution of Arbitrary Code via SaveLanguageFiles Method
CVE-2024-31822
9.8CRITICAL
What is CVE-2024-31822?
A vulnerability exists in the Ecommerce-CodeIgniter-Bootstrap framework, allowing remote attackers to execute arbitrary code. This security flaw resides in the saveLanguageFiles method of the Languages.php component, which can be exploited by sending specially crafted requests. As a result, unauthorized access to sensitive systems and data can occur, posing significant risks to affected applications. Users of Ecommerce-CodeIgniter-Bootstrap are advised to review their implementations and remediate the issue promptly to safeguard their environments.
