CVE-2026-14634 | kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517 Subscribed Emails Admin Page MY_Controller.php checkForPostRequests User-Agent cross site scripting (GHSA-v69c-5xg5-q7r8)
A vulnerability labeled as problematic has been found in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 213babdbaa949e94557246414db0130e01394517. This vulnerability affects the function checkForPostRequests of the file application/core/MY_Controller.php of the component Subscribed Emails Admin Page. Such manipulation of the argument User-Agent leads to cross site scripting.
This vulnerability is listed as CVE-2026-14634. The attack may be performed from remote. In addition, an exploit is available.
This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. It is advisable to implement a patch to correct this issue.VulDB Recent EntriesRead More