PT-2026-31317 · Ci4Ms · Ci4Ms

Published

2026-04-08

·

Updated

2026-04-08

·

CVE-2026-39390

CVSS v3.1

5.5

Medium

AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CI4MS versions prior to 0.31.4.0
Description CI4MS is a CodeIgniter 4-based CMS skeleton. Prior to version 0.31.4.0, the Google Maps iframe setting (cMap field) in the compInfosPost() function does not properly sanitize the srcdoc attribute, allowing an attacker with admin access to inject a malicious iframe payload with HTML-entity-encoded JavaScript. This injected code executes in the context of the parent page when viewed by unauthenticated users.
Recommendations Update to version 0.31.4.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-39390
GHSA-X3HR-CP7X-44R2

Affected Products

Ci4Ms