CI4MS是Ci4MS开源的一个博客页面管理工具。 CI4MS 0.31.4.0之前版本存在安全漏洞,该漏洞源于安装控制器读取host参数时未经验证即写入.env文件,且未剥离换行符,可能导致攻击者注入任意配置指令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-39393 | 8.1 HIGH | Post-Installation Re-entry via Cache-Dependent Install Guard Bypass in ci4ms |
| CVE-2026-39389 | 6.7 MEDIUM | CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Wri |
| CVE-2026-39390 | 5.5 MEDIUM | CI4MS has Stored XSS via srcdoc attribute bypass in Google Maps iframe setting |
| CVE-2026-39392 | 5.5 MEDIUM | CI4MS has Stored XSS in Pages Content Due to Missing html_purify Sanitization |
| CVE-2026-39391 | 4.8 MEDIUM | CI4MS has Stored XSS via Unescaped Blacklist Note in Admin User List |
No comments yet