在 aaPanel(宝塔面板)直至 11.8.0 版本中发现了一个安全漏洞。该漏洞影响了组件“域名处理器”(Domain Handler)中文件 的 函数。通过对 参数的操控,可导致 SQL 注入。攻击者可远程发起攻击。目前该漏洞的利用代码已公开,可能被用于实际攻击。厂商已在披露早期被联系,但并未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101008 | 9.1 CRITICAL | aaPanel BaoTa File Merge files.py merge_split_file command injection |
| CVE-2026-101007 | 8.4 HIGH | aaPanel BaoTa Database Backup database.py InputSql os command injection |
| CVE-2026-101009 | 8.4 HIGH | aaPanel BaoTa Unzip panelTask.py panelTask.bt_task._unzip os command injection |
| CVE-2026-101010 | 4.7 MEDIUM | aaPanel BaoTa data.py getData sql injection |
No comments yet