CVE-2026-34561: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34561 is a stored DOM-based Cross-Site Scripting (XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton with RBAC authorization and theme support. The flaw exists in the System Settings – Social Media Management module, where user-controlled input in Social Media and Social Media Link fields is stored server-side and rendered without proper output encoding. All versions up to and including 0.28.6.0 are affected; the issue was patched in version 0.31.0.0. The advisory was published on March 31, 2026, and assigned a CVSS v3.1 base score of 9.1 (Critical) by GitHub Advisory, though NVD records a score of 8.4 (High) (Github Advisory, CI4MS Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a stored DOM XSS variant where attacker-controlled input breaks out of HTML input attribute context on the same settings page (/backend/settings/) (Github Advisory). Unlike typical stored XSS that executes on public-facing pages, this payload executes immediately upon re-rendering the Social Media Management settings page in the authenticated user's browser, without requiring a separate victim to visit a different page. Exploitation requires high privileges (administrator-level access) to submit configuration values, but no additional user interaction is needed once the payload is stored — the script fires automatically when the settings page is loaded. A proof-of-concept payload demonstrating attribute context breakout is publicly documented: test"><img src=1 onerror=alert()>" class="form-control" placeholder="Name" required> (CI4MS Advisory).

Impact

Successful exploitation enables persistent execution of arbitrary JavaScript in the browsers of any authenticated user who views the Social Media Management settings page, including other administrators. This can lead to full administrator account takeover, privilege escalation across all roles, session cookie theft, and complete platform compromise. Because the payload persists in the application's configuration store, every subsequent page load by any privileged user triggers the malicious script, amplifying the blast radius beyond the initial attacker's session (Github Advisory, CI4MS Advisory).

Exploitability

A proof-of-concept exploit with step-by-step reproduction instructions is publicly available in the GitHub Security Advisory, including a video PoC hosted externally (CI4MS Advisory). There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.038% (0.000380), placing it in the 24th percentile for exploitation probability within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Authenticate as Administrator: Log in to the CI4MS backend with an account that has administrative privileges sufficient to access System Settings.
  2. Navigate to the vulnerable endpoint: Browse to System Settings → Social Media Management (endpoint: /backend/settings/).
  3. Inject the XSS payload: In any Social Media Name or Social Media Link field, insert a payload that breaks out of the HTML input attribute context, such as: test"><img src=1 onerror=alert()>" class="form-control" placeholder="Name" required>
  4. Save the settings: Submit the form to persist the malicious payload in the server-side configuration store.
  5. Trigger execution: The payload executes immediately on the same page upon save, and will re-execute every time any authenticated user (including other administrators) loads the Social Media Management settings page.
  6. Escalate impact: Replace the alert() with a more harmful payload (e.g., cookie exfiltration via document.cookie, credential harvesting, or CSRF-via-XSS) to achieve session hijacking, account takeover, or lateral privilege escalation across all roles (CI4MS Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from the CI4MS server or from administrator browsers to unknown external domains, potentially carrying encoded cookie or session data as query parameters or POST bodies.
  • Logs: Web server access logs showing POST requests to /backend/settings/ containing HTML special characters (<, >, ", onerror, alert, script) in Social Media configuration fields; repeated access to the settings page by multiple distinct admin accounts in a short timeframe.
  • Application Data: Social Media Name or Social Media Link fields in the database or configuration store containing HTML tags, JavaScript event handlers (e.g., onerror, onload), or <script> elements.
  • Browser/Session: Unexpected session invalidation or new admin sessions created from unfamiliar IP addresses shortly after an administrator visited the settings page (CI4MS Advisory).

Mitigation and workarounds

The vendor has released a patch in CI4MS version 0.31.0.0, which implements global input validation, enhanced XSS protection, and CSRF token improvements as part of a major security and framework update (CI4MS Release). All users running version 0.28.6.0 or earlier should upgrade immediately; it is recommended to back up the database and run composer update before upgrading due to major structural changes including Shield authentication migration. As interim workarounds for environments that cannot immediately upgrade, administrators should implement strict HTML entity encoding on all user-controlled data before rendering, avoid unsafe DOM manipulation methods (innerHTML, .html()), enforce a Content Security Policy (CSP), and set HttpOnly, SameSite, and Secure flags on session cookies (Github Advisory).

Community reactions

The vulnerability was reported by researchers credited as bugmithlegend and LAW6ZX7 in the GitHub Security Advisory (CI4MS Advisory). The advisory was noted by automated CVE tracking feeds including cvefeed.io and radar.offseq.com shortly after publication, and the CVE was picked up by the ENISA European Vulnerability Database (EUVD-2026-18073). No significant broader media coverage or notable security researcher commentary beyond the advisory itself has been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management