PT-2026-99786 · Unknown · Aapanel Baota
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
aaPanel BaoTa versions prior to 11.8.1
Description
A security flaw in the Domain Handler component allows for remote SQL injection. The issue exists within the
get domain status() function located in the /www/server/panel/mod/project/domain/domainMod.py file. An attacker can trigger this by manipulating the get argument. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.Recommendations
Update aaPanel BaoTa to a version newer than 11.8.0.
As a temporary mitigation, restrict access to the
get domain status() function within the Domain Handler component.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aapanel Baota