CVE-2026-34557 | ci4-cms-erp ci4ms 0.28.5.0 Permission Management Page cross site scripting (GHSA-rpjr-985c-qhvm)
A vulnerability, which was classified as problematic, was found in ci4-cms-erp ci4ms 0.28.5.0. This impacts an unknown function of the component Permission Management Page. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2026-34557. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.