Home
MEDIUM: 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N >= 0.26.0, < 0.31.8.0
affected
Description
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0 to before version 0.31.8.0, the auth filter has the deactivated/banned user check commented out. This issue has been patched in version 0.31.8.0.
Problem types
CWE-613: Insufficient Session Expiration
Product status
References
github.com/.../ci4ms/security/advisories/GHSA-5hfv-c864-qcq9
github.com/ci4-cms-erp/ci4ms/releases/tag/0.31.8.0