Description

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.31.1.0 to before version 0.31.8.0, the deleteProcess() action accepts a POST parameter tables[] containing arbitrary table names. These are passed directly to $forge->dropTable() without validating that the tables belong to the theme being deleted. The deleteConfirm view correctly populates tables[] from the theme's own migration files, but the server-side deleteProcess does not verify the received values against those files. An authenticated admin can craft a POST request with arbitrary table names and drop any table in the database. This issue has been patched in version 0.31.8.0.

INFO

Published Date :

2026-05-07T03:23:31.339Z

Last Modified :

2026-05-07T13:42:35.440Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-41890 vulnerability.

Vendors Products
Ci4-cms-erp
  • Ci4ms
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-41890.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability