File Editor Module Vulnerability in CI4MS by CI4CMS
CVE-2026-45139

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-45139?

The CI4MS content management system, based on CodeIgniter 4, suffers from a critical file editor module issue. Previous to version 0.31.9.0, the system's Fileeditor module implements a restrictive extension allowlist for certain file operations, but inadequately validates file paths for destructive actions like unlinking or renaming. This flaw allows a backend user with file-editor permissions to manipulate crucial files outside the established blocklist, risking permanent deletion of critical frameworks and files essential for system operation. The identified files include app configuration and routing files and common entry points. Recovery from such deletions necessitates a full filesystem restoration. Version 0.31.9.0 introduces a patch to effectively address this vulnerability.

Affected Version(s)

ci4ms < 0.31.9.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.