PT-2026-99786 · Unknown · Aapanel Baota

·

CVE-2026-101011

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions aaPanel BaoTa versions prior to 11.8.1
Description A security flaw in the Domain Handler component allows for remote SQL injection. The issue exists within the get domain status() function located in the /www/server/panel/mod/project/domain/domainMod.py file. An attacker can trigger this by manipulating the get argument. SQL injection is a technique where malicious SQL statements are inserted into entry fields for execution, potentially allowing unauthorized access to the database.
Recommendations Update aaPanel BaoTa to a version newer than 11.8.0. As a temporary mitigation, restrict access to the get domain status() function within the Domain Handler component.

Exploit

Fix

Special Elements Injection

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101011

Affected Products

Aapanel Baota