PT-2026-29127 · Ci4Ms · Ci4Ms

Bugmithlegend

+1

·

Published

2026-03-30

·

Updated

2026-04-01

·

CVE-2026-34557

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions CI4MS versions prior to 0.31.0.0
Description CI4MS is a CodeIgniter 4-based CMS skeleton offering a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.0.0, the application does not properly sanitize user-controlled input within group and role management functionality. Multiple input fields related to groups can be injected with malicious JavaScript payloads, which are then stored on the server. These stored payloads are rendered unsafely within privileged administrative views without proper output encoding, leading to stored cross-site scripting (XSS) within the role and permission management context. The issue allows for privilege escalation to administrative levels. The affected input fields are related to group management.
Recommendations Versions prior to 0.31.0.0 should be updated to version 0.31.0.0 or later.

Exploit

Fix

LPE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34557
GHSA-RPJR-985C-QHVM

Affected Products

Ci4Ms