Tag
high
threat
CVE-2026-9517: CodeIgniter-StudentManagementSystem Improper Access Control
2 rules 2 TTPs 1 CVEA vulnerability in hemant6488 CodeIgniter-StudentManagementSystem allows remote attackers to perform improper access controls by manipulating the /index.php/students/addStudentView file, with a publicly available exploit and no vendor response.
CodeIgniter-StudentManagementSystem
cve
access-control
codeigniter
2r
2t
1c
critical
advisory
CI4MS Theme Upload Zip Slip Vulnerability
2 rules 2 TTPsA critical vulnerability exists in ci4ms Theme::upload, where improper validation of ZIP archive entry names allows authenticated users with theme creation permissions to write files to arbitrary locations, leading to remote code execution.
ci4-cms-erp/ci4ms
zip-slip
rce
codeigniter
vulnerability
2r
2t