{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/phpsysinfo/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["phpSysInfo (\u003c= 3.4.5)"],"_cs_severities":["high"],"_cs_tags":["web-application","vulnerability","cve-2026-55584"],"_cs_type":"threat","_cs_vendors":["phpSysInfo"],"content_html":"\u003cp\u003ephpSysInfo versions 3.4.5 and earlier contain a critical configuration vulnerability (CVE-2026-55584) related to how the application determines the client's IP address. The application uses a trust-all approach to HTTP headers such as 'X-Forwarded-For' and 'Client-IP' to verify if a request originates from an authorized address defined in the PSI_ALLOWED configuration. Because there is no mechanism to validate that these headers are coming from a trusted proxy, an unauthenticated remote attacker can inject an authorized IP address into these headers. This manipulation defeats the allowlist protection and provides the attacker with access to the full system information XML exposed through the 'xml.php' endpoint, which contains system configuration, hardware details, and potentially sensitive environment data. This vulnerability was addressed in version 3.4.6.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify a target web server running phpSysInfo 3.4.5.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with 'xml.php' to confirm that IP allowlisting is enforced, receiving a 'Client IP address ... not allowed' message.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the target's IP allowlist configuration by trial or auxiliary discovery if applicable.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request to 'xml.php'.\u003c/li\u003e\n\u003cli\u003eAttacker injects the 'X-Forwarded-For' or 'Client-IP' HTTP header containing an IP address authorized in the application's configuration.\u003c/li\u003e\n\u003cli\u003eThe web server passes the spoofed header to the vulnerable 'read_config.php' logic.\u003c/li\u003e\n\u003cli\u003eThe application incorrectly validates the spoofed header as the source IP and grants access.\u003c/li\u003e\n\u003cli\u003eThe application serves the sensitive system information XML to the unauthorized attacker.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to gain unauthorized access to system-level diagnostic and configuration information that is intended to be restricted to specific administrative IP addresses. This information disclosure can facilitate further attacks by revealing underlying system architecture, kernel versions, hardware components, and potentially sensitive environment paths or configuration details.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of phpSysInfo to version 3.4.6 or later immediately to implement trusted proxy validation.\u003c/li\u003e\n\u003cli\u003eApply the Sigma rule provided below to monitor for incoming HTTP requests that use non-standard IP-identifying headers in a way that suggests exploitation attempts.\u003c/li\u003e\n\u003cli\u003eConfigure the web server (e.g., Apache/Nginx) to ignore or scrub 'X-Forwarded-For' and 'Client-IP' headers from external requests unless they originate from a known, trusted internal proxy.\u003c/li\u003e\n\u003cli\u003eReview access logs for 'xml.php' requests originating from unexpected IP addresses that also contain 'X-Forwarded-For' headers, which may indicate exploitation attempts against this CVE.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-17T14:54:01Z","date_published":"2026-08-17T14:54:01Z","id":"https://feed.craftedsignal.io/briefs/2026-08-phpsysinfo-bypass/","summary":"A vulnerability in phpSysInfo 3.4.5 and earlier allows unauthenticated attackers to bypass IP-based access controls by spoofing HTTP headers, potentially exposing sensitive system information via xml.php.","title":"phpSysInfo IP Allowlist Bypass","url":"https://feed.craftedsignal.io/briefs/2026-08-phpsysinfo-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - PhpSysInfo","version":"https://jsonfeed.org/version/1.1"}