PT-2026-29127 · Ci4Ms · Ci4Ms

Bugmithlegend

+1

·

Publicado

2026-03-30

·

Atualizado

2026-04-01

·

CVE-2026-34557

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions CI4MS versions prior to 0.31.0.0
Description CI4MS is a CodeIgniter 4-based CMS skeleton offering a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application does not properly sanitize user-controlled input within group and role management functionality. Multiple input fields related to groups can be injected with malicious JavaScript payloads, which are then stored on the server. These stored payloads are rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. The issue allows for privilege escalation to administrative levels. The affected input fields are related to group management.
Recommendations Versions prior to 0.31.0.0 should be updated to version 0.31.0.0 or later.

Exploit

Correção

LPE

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-34557
GHSA-RPJR-985C-QHVM

Produtos afetados

Ci4Ms