CVE 9.4 CRITICAL

ci4ms Backup::restore is vulnerable to Zip Slip leading to RCE_CVE-2026-41202

9.4 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.5.0, ci4ms Backup::restore extracts user uploaded ZIP archives without validating entry names, allowing an authenticated backend user with the backup create permission to write files to arbitrary filesystem locations (Zip Slip) and achieve remote code execution by dropping a PHP file under the public web root. This issue has been patched in version 0.31.5.0.

AI Analysis

ci4ms Backup::restore is vulnerable to Zip Slip, allowing remote code execution by dropping a PHP file under the public web root

Basic Information

ID CVE-2026-41202
Source GitHub_M
Published May 7, 2026 at 03:18

Affected Product

Vendor ci4-cms-erp
Product ci4ms
Version < 0.31.5.0
Affected Versions ci4-cms-erp ci4ms < 0.31.5.0

CWE Classification

AI Assessment

AI Score 9.4 / 10
AI Severity Critical
Vendor ci4-cms-erp
Product ci4ms
Version < 0.31.5.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.