CVE-2026-41202 | ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0/0.31.4.0 PHP File Backup::restore path traversal (GHSA-xp9f-pvvc-57p4)
A vulnerability, which was classified as critical, was found in ci4-cms-erp ci4ms 0.28.5.0/0.31.0.0/0.31.2.0/0.31.4.0. Affected by this vulnerability is the function Backup::restore of the component PHP File Handler. Such manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-41202. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.