CVE-2026-45139 PUBLISHED

CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations

Assigner: GitHub_M
Reserved: 08.05.2026 Published: 20.07.2026 Updated: 20.07.2026

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (['css','js','html','txt','json','sql','md']) on content-write operations (saveFile, createFile), but two destructive endpoints — deleteFileOrFolder and renameFile — never validate the extension of the source path. A backend user with file-editor permissions can therefore unlink or rename any file inside the project root that is not explicitly listed in the small $hiddenItems blocklist. Critical framework files such as app/Config/Routes.php, app/Config/App.php, app/Config/Database.php, app/Config/Filters.php, public/index.php, and public/.htaccess all live outside that blocklist and can be destroyed, producing a persistent denial of service that requires filesystem-level redeployment to recover. Version 0.31.9.0 patches the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
CVSS Score: 6.5

Product Status

Vendor ci4-cms-erp
Product ci4ms
Versions
  • Version < 0.31.9.0 is affected

References

Problem Types

  • CWE-73: External Control of File Name or Path CWE