CVE-2026-45139 | ci4-cms-erp CI4MS up to 0.31.8.0 Fileeditor app/Config/Routes.php deleteFileOrFolder/renameFile hiddenItems input validation
A vulnerability classified as problematic has been found in ci4-cms-erp CI4MS up to 0.31.8.0. This vulnerability affects the function deleteFileOrFolder/renameFile of the file app/Config/Routes.php of the component Fileeditor. The manipulation of the argument hiddenItems leads to improper input validation.
This vulnerability is listed as CVE-2026-45139. The attack may be initiated remotely. There is no available exploit.