
`CI4MS` Menu Management is susceptible to a Stored DOM #XSS vulnerability (CVE-2026-34565) allowing account takeover and privilege escalation. Investigate deployments and apply input validation/output encoding. #infosec #vulnerability https://www.pulsepatch.io/posts/cve-2026-34565-ci4ms-stored-dom-xss-account-takeover
Post summary
The advisory discloses a stored DOM XSS vulnerability (CVE‑2026‑34565) in CI4MS Menu Management that allows account takeover and privilege escalation, and recommends applying input validation/output encoding as a mitigation.



