Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

phpSysInfo 3.4.5 - IP Allowlist Bypass

0
Medium
VulnerabilityCVE-2026-55584exploitlinuxcvephp
Published: 08/17/2026 (08/17/2026, 00:00:00 UTC)
Source: Exploit-DB RSS Feed

Description

phpSysInfo version 3.4.5 and earlier contains an IP allowlist bypass vulnerability. The application determines the client IP address by first checking the X-Forwarded-For and Client-IP HTTP headers, which can be attacker-controlled, before falling back to the more trustworthy REMOTE_ADDR. Because there is no trusted-proxy configuration, an attacker can spoof an allowed IP address via these headers and bypass the IP allowlist restriction to access sensitive system information exposed through xml.php. This vulnerability is fixed in version 3.4.6 by restricting the use of these headers to requests from trusted proxies only.

Affected software

GitHub Actionsmore threats →ai
phpsysinfo/phpsysinfo
pkg:github/phpsysinfo/phpsysinfo
Affected versions
<=3.4.5

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 22:16:24 UTC

Technical Analysis

The vulnerability (CVE-2026-55584) in phpSysInfo 3.4.5 and earlier arises from improper client IP address validation in the IP allowlist feature. The code prioritizes the X-Forwarded-For and Client-IP headers over REMOTE_ADDR without verifying if the request comes from a trusted proxy. This allows an attacker to spoof an allowed IP address in these headers and bypass the IP allowlist, gaining unauthorized access to full system information via the xml.php endpoint. The issue is resolved in version 3.4.6 by changing the logic to default to REMOTE_ADDR and only honor X-Forwarded-For and Client-IP headers from configured trusted proxies.

Potential Impact

An attacker can bypass the IP allowlist intended to restrict access to sensitive system information. This allows unauthorized disclosure of full system details exposed by the xml.php interface. The impact is information disclosure, which could aid further attacks or reconnaissance.

Mitigation Recommendations

A fix is available in phpSysInfo version 3.4.6. Users should upgrade to this version or later to ensure the IP allowlist properly validates client IP addresses by honoring X-Forwarded-For and Client-IP headers only from trusted proxies. Until upgraded, relying on the IP allowlist for access control is insecure.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Cve
CVE-2026-55584
Version
<= 3.4.5
Author
Muhammed Mirac Kayikci
Platform
Linux
Edb Id
52648
Has Exploit Code
true
Code Language
text

Indicators of Compromise

Exploit Source Code

Exploit Code

Exploit code for phpSysInfo 3.4.5 - IP Allowlist Bypass

# Exploit Title: phpSysInfo  3.4.5 - IP Allowlist Bypass 
# Google Dork: N/A
# Date: 2026-07-11
# Exploit Author: Muhammed Mirac Kayikci
# Vendor Homepage: https://phpsysinfo.github.io/phpsysinfo/
# Software Link: https://github.com/phpsysinfo/phpsysinfo/archive/refs/tags/v3.4.5.tar.gz
# Version: <= 3.4.5
# Tested on: Linux (Apache/PHP)
# CVE : CVE-2026-55584

References:
-----------
GHSA: https://github.com/phpsysinfo/phpsysinfo/security/advisories/GHSA-786w-p5pm-cvgh
CVE:  https://www.cve.org/
... (1321 more characters)
Code Length: 1,821 characters

Threat ID: 6a838813bf8831d539a900bd

Added to database: 08/17/2026, 22:15:47 UTC

Last enriched: 08/17/2026, 22:16:24 UTC

Last updated: 08/18/2026, 01:02:45 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses