Summary

CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules

Advisory details

Impact

This is an unsafe file upload validation vulnerability that can lead to remote code execution in vulnerable application configurations.

Applications are impacted when they:

  • validate uploads using is_image or mime_in without an independent safe extension check, such as ext_in on patched versions
  • save uploaded files using the client-supplied filename
  • place uploads in a web-accessible directory where PHP files can execute

Patches

Upgrade to v4.7.4 or later.

Workarounds

  • Save uploads outside the public web root, preferably under writable/uploads.
  • Use $file->store() or $file->move($path, $file->getRandomName()) instead of preserving the original client filename.
  • Disable script execution in any public upload directory.
  • Manually verify the client filename extension before moving the file.
  • For image uploads, reject files when $file->getClientExtension() is not an allowed image extension.
  • For exact MIME-type validation, reject files when $file->getClientExtension() does not match $file->guessExtension().

References