PT-2026-41769 · Packagist+2 · Ci4-Cms-Erp/Ci4Ms+1
CVE-2026-45139
·
Published
2026-05-18
·
Updated
2026-07-21
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CI4MS versions prior to 0.31.9.0
Description
The Fileeditor module fails to validate the file extension of the source path in the
deleteFileOrFolder and renameFile endpoints. While content-write operations like saveFile and createFile use an extension allowlist, these destructive endpoints only check if the path is within the project root and not in a small blocklist of hidden items. Consequently, a backend user with file-editor permissions can delete or rename critical framework files, such as app/Config/Routes.php, app/Config/App.php, app/Config/Database.php, app/Config/Filters.php, public/index.php, and public/.htaccess. This can lead to a persistent denial of service that requires filesystem-level redeployment to recover.Recommendations
Update to version 0.31.9.0.
As a temporary workaround, restrict the
fileeditor.delete and fileeditor.update permissions to only highly trusted superadministrators.Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ci4-Cms-Erp/Ci4Ms
Ci4Ms