File Editor Module Vulnerability in CI4MS by CI4CMS
CVE-2026-45139
What is CVE-2026-45139?
The CI4MS content management system, based on CodeIgniter 4, suffers from a critical file editor module issue. Previous to version 0.31.9.0, the system's Fileeditor module implements a restrictive extension allowlist for certain file operations, but inadequately validates file paths for destructive actions like unlinking or renaming. This flaw allows a backend user with file-editor permissions to manipulate crucial files outside the established blocklist, risking permanent deletion of critical frameworks and files essential for system operation. The identified files include app configuration and routing files and common entry points. Recovery from such deletions necessitates a full filesystem restoration. Version 0.31.9.0 introduces a patch to effectively address this vulnerability.
Affected Version(s)
ci4ms < 0.31.9.0
