CVE-2022-40824
CodeIgniter vulnerability analysis and mitigation

Overview

CodeIgniter version 3.1.13 and earlier was reported to contain a potential SQL Injection vulnerability via the orwhere() function in system\database\DBquery_builder.php. This vulnerability was disclosed in September 2022 and assigned identifier CVE-2022-40824. However, it's important to note that this vulnerability is disputed, with multiple third parties questioning its validity as a legitimate security issue (NVD, Debian).

Technical details

The vulnerability was reported to exist in the orwhere() function within the DBquery_builder.php component of CodeIgniter's database system. The issue allegedly stems from insufficient filtering of query fields, which could potentially lead to SQL injection if developers incorrectly handle client-side input (MITRE).

Impact

If the vulnerability were to be exploited successfully, it could potentially allow attackers to manipulate SQL queries, potentially leading to unauthorized access to database contents. However, given the disputed nature of this vulnerability, the actual impact may be minimal or non-existent (NVD).

Mitigation and workarounds

Given the disputed nature of this vulnerability and lack of official confirmation, no specific patches or mitigations have been issued. However, as a general security practice, it's recommended to properly validate and sanitize all user input before using it in database queries (NVD).

Additional resources


SourceThis report was generated using AI

Related CodeIgniter vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-54418CRITICAL9.8
  • PHPPHP
  • cpe:2.3:a:codeigniter:codeigniter
NoYesJul 28, 2025
CVE-2024-41344HIGH7.5
  • CodeIgniterCodeIgniter
  • cpe:2.3:a:codeigniter:codeigniter
NoYesOct 15, 2024
CVE-2024-29904HIGH7.5
  • PHPPHP
  • codeigniter4/framework
NoYesMar 29, 2024
CVE-2025-45406MEDIUM6.1
  • PHPPHP
  • cpe:2.3:a:codeigniter:codeigniter
NoYesJul 25, 2025
CVE-2025-24013MEDIUM5.3
  • PHPPHP
  • cpe:2.3:a:codeigniter:codeigniter
NoYesJan 20, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management