
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27599 is a Stored DOM Cross-Site Scripting (XSS) vulnerability in the ci4ms CMS/ERP platform (ci4-cms-erp/ci4ms), a Composer-based PHP application. The vulnerability exists in the System Settings – Mail Settings configuration module, where multiple fields fail to sanitize user-controlled input before storing and re-rendering it. All versions up to and including 0.28.6.0 are affected; version 0.31.0.0 contains the fix. It was published on March 30, 2026, with a CVSS v3.1 score of 9.1 (Critical) per the GitHub Advisory Database (GitHub Advisory, GHSA-66m2-v9v9-95c3).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where the application uses unsafe rendering methods (e.g., .html() or innerHTML-style sinks) to display stored configuration values without output encoding. Affected fields include Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings at the /backend/settings/ endpoint. An attacker with administrative credentials can inject a payload such as test"><img src=1 onerror=alert()> into any of these fields; upon saving, the payload breaks out of the HTML attribute context and executes immediately on the same settings page when rendered by the browser. The vulnerability is classified as same-page DOM-based stored XSS, distinct from reflected or landing-page XSS (GitHub Advisory, GHSA-66m2-v9v9-95c3).
Successful exploitation enables persistent execution of arbitrary JavaScript in the browser session of any administrator who views the Mail Settings page, allowing session token theft, unauthorized modification of application settings, privilege escalation, and full account takeover across all user roles. Because the payload is stored server-side and executes without requiring additional user interaction beyond page load, the impact extends to full platform compromise — any administrator visiting the settings page is affected. The CVSS scope is rated as Changed, reflecting the potential for the injected script to affect resources beyond the immediate settings component (GitHub Advisory, GHSA-66m2-v9v9-95c3).
A proof-of-concept exploit with step-by-step reproduction instructions is publicly available in the GitHub Security Advisory, including the specific endpoint, affected field names, and a working XSS payload (GHSA-66m2-v9v9-95c3). A video PoC is also referenced in the advisory. Exploitation requires high privileges (administrative access), which limits the attack surface but does not eliminate risk in environments with compromised or malicious admin accounts. The EPSS score is approximately 0.034% (10th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (GitHub Advisory).
System Settings → Mail Settings at /backend/settings/.test"><img src=1 onerror=alert(document.cookie)>. Other fields such as Mail Port, Email Address, Email Password, Mail Protocol, or TLS settings are equally injectable.document.cookie in XSS payloads); unusual POST requests to /backend/settings/ containing HTML/JavaScript special characters (<, >, ", onerror, alert, script)./backend/settings/ with URL-encoded XSS payloads in request bodies; application logs recording unusual or malformed values in mail configuration fields.onerror, onload), or <script> tags in fields such as mail_server, mail_port, email_address, or mail_protocol.Update ci4ms to version 0.31.0.0 or later, which contains the patch for this vulnerability (GitHub Advisory). As interim mitigations: apply proper HTML output encoding for all mail configuration fields and avoid using innerHTML-style rendering sinks for user-controlled data; implement a strict Content Security Policy (CSP) to block inline script execution; enforce HttpOnly, SameSite, and Secure flags on session cookies to reduce XSS impact; and restrict access to System Settings to the minimum number of trusted administrators. A full audit of other system settings fields for similar attribute injection vulnerabilities is also recommended (GHSA-66m2-v9v9-95c3).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."