Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-45139

Опубликовано: 20 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (['css','js','html','txt','json','sql','md']) on content-write operations (saveFile, createFile), but two destructive endpoints — deleteFileOrFolder and renameFile — never validate the extension of the source path. A backend user with file-editor permissions can therefore unlink or rename any file inside the project root that is not explicitly listed in the small $hiddenItems blocklist. Critical framework files such as app/Config/Routes.php, app/Config/App.php, app/Config/Database.php, app/Config/Filters.php, public/index.php, and public/.htaccess all live outside that blocklist and can be destroyed, producing a persistent denial of service that requires filesystem-level redeployment to recover. Version 0.31.9.0 patches the issue.

EPSS

Процентиль: 19%
0.00267
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 6.5
github
2 месяца назад

CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations

EPSS

Процентиль: 19%
0.00267
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-73