PT-2026-41769 · Packagist+2 · Ci4-Cms-Erp/Ci4Ms+1

CVE-2026-45139

·

Published

2026-05-18

·

Updated

2026-07-21

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions CI4MS versions prior to 0.31.9.0
Description The Fileeditor module fails to validate the file extension of the source path in the deleteFileOrFolder and renameFile endpoints. While content-write operations like saveFile and createFile use an extension allowlist, these destructive endpoints only check if the path is within the project root and not in a small blocklist of hidden items. Consequently, a backend user with file-editor permissions can delete or rename critical framework files, such as app/Config/Routes.php, app/Config/App.php, app/Config/Database.php, app/Config/Filters.php, public/index.php, and public/.htaccess. This can lead to a persistent denial of service that requires filesystem-level redeployment to recover.
Recommendations Update to version 0.31.9.0. As a temporary workaround, restrict the fileeditor.delete and fileeditor.update permissions to only highly trusted superadministrators.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45139
GHSA-245J-XJVR-XVM5

Affected Products

Ci4-Cms-Erp/Ci4Ms
Ci4Ms