CVE-2026-27599: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-27599 is a Stored DOM Cross-Site Scripting (XSS) vulnerability in the ci4ms CMS/ERP platform (ci4-cms-erp/ci4ms), a Composer-based PHP application. The vulnerability exists in the System Settings – Mail Settings configuration module, where multiple fields fail to sanitize user-controlled input before storing and re-rendering it. All versions up to and including 0.28.6.0 are affected; version 0.31.0.0 contains the fix. It was published on March 30, 2026, with a CVSS v3.1 score of 9.1 (Critical) per the GitHub Advisory Database (GitHub Advisory, GHSA-66m2-v9v9-95c3).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where the application uses unsafe rendering methods (e.g., .html() or innerHTML-style sinks) to display stored configuration values without output encoding. Affected fields include Mail Server, Mail Port, Email Address, Email Password, Mail Protocol, and TLS settings at the /backend/settings/ endpoint. An attacker with administrative credentials can inject a payload such as test"><img src=1 onerror=alert()> into any of these fields; upon saving, the payload breaks out of the HTML attribute context and executes immediately on the same settings page when rendered by the browser. The vulnerability is classified as same-page DOM-based stored XSS, distinct from reflected or landing-page XSS (GitHub Advisory, GHSA-66m2-v9v9-95c3).

Impact

Successful exploitation enables persistent execution of arbitrary JavaScript in the browser session of any administrator who views the Mail Settings page, allowing session token theft, unauthorized modification of application settings, privilege escalation, and full account takeover across all user roles. Because the payload is stored server-side and executes without requiring additional user interaction beyond page load, the impact extends to full platform compromise — any administrator visiting the settings page is affected. The CVSS scope is rated as Changed, reflecting the potential for the injected script to affect resources beyond the immediate settings component (GitHub Advisory, GHSA-66m2-v9v9-95c3).

Exploitability

A proof-of-concept exploit with step-by-step reproduction instructions is publicly available in the GitHub Security Advisory, including the specific endpoint, affected field names, and a working XSS payload (GHSA-66m2-v9v9-95c3). A video PoC is also referenced in the advisory. Exploitation requires high privileges (administrative access), which limits the attack surface but does not eliminate risk in environments with compromised or malicious admin accounts. The EPSS score is approximately 0.034% (10th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (GitHub Advisory).

Exploitation steps

  1. Gain Administrative Access: Obtain valid administrator credentials for the ci4ms application (e.g., through credential theft, phishing, or reuse of leaked credentials).
  2. Navigate to the Vulnerable Endpoint: Log in and browse to System Settings → Mail Settings at /backend/settings/.
  3. Inject XSS Payload: Enter the following payload into any Mail Settings field (e.g., Mail Server): test"><img src=1 onerror=alert(document.cookie)>. Other fields such as Mail Port, Email Address, Email Password, Mail Protocol, or TLS settings are equally injectable.
  4. Save the Settings: Submit the form to store the malicious payload server-side.
  5. Trigger Execution: The payload executes immediately upon page render — either for the attacker or for any other administrator who subsequently visits the Mail Settings page. The script breaks out of the HTML attribute context and runs in the victim's browser session.
  6. Achieve Objective: Use the executing JavaScript to steal session tokens, perform unauthorized actions as the administrator, escalate privileges, or achieve full platform compromise (GHSA-66m2-v9v9-95c3).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from the admin browser session to attacker-controlled domains (e.g., for cookie exfiltration via document.cookie in XSS payloads); unusual POST requests to /backend/settings/ containing HTML/JavaScript special characters (<, >, ", onerror, alert, script).
  • Logs: Web server access logs showing POST requests to /backend/settings/ with URL-encoded XSS payloads in request bodies; application logs recording unusual or malformed values in mail configuration fields.
  • File System / Database: Mail settings database records containing HTML tags, JavaScript event handlers (e.g., onerror, onload), or <script> tags in fields such as mail_server, mail_port, email_address, or mail_protocol.
  • Browser / Session: Unexpected JavaScript execution or alert dialogs when administrators visit the Mail Settings page; session tokens appearing in outbound network requests to third-party domains (GHSA-66m2-v9v9-95c3).

Mitigation and workarounds

Update ci4ms to version 0.31.0.0 or later, which contains the patch for this vulnerability (GitHub Advisory). As interim mitigations: apply proper HTML output encoding for all mail configuration fields and avoid using innerHTML-style rendering sinks for user-controlled data; implement a strict Content Security Policy (CSP) to block inline script execution; enforce HttpOnly, SameSite, and Secure flags on session cookies to reduce XSS impact; and restrict access to System Settings to the minimum number of trusted administrators. A full audit of other system settings fields for similar attribute injection vulnerabilities is also recommended (GHSA-66m2-v9v9-95c3).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management