PT-2026-29117 · Ci4 Cms Erp · Ci4Ms
Published
2026-03-30
·
Updated
2026-03-30
·
CVE-2026-27599
CVSS v3.1
4.7
Medium
| AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L |
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application fails to properly sanitize user-controlled input within System Settings – Mail Settings. Several configuration fields, including Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings, accept attacker-controlled input that is stored server-side and later rendered without proper output encoding. This issue has been patched in version 0.31.0.0.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ci4Ms