CtrlPanel.gg是CtrlPanel.gg开源的一款主机服务计费管理工具。 CtrlPanel.gg 1.1.1及之前版本存在安全漏洞,该漏洞源于管理设置更新端点接受用户提供的类名并用于动态调用,未进行白名单验证,导致认证远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ctrlpanel-gg | panel | < 1.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ctrlpanel-gg | panel | < 1.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34234 | 10.0 CRITICAL | CtrlPanel: Unauthenticated RCE using installer script |
| CVE-2026-34241 | 8.7 HIGH | CtrlPanel: Stored XSS in Ticket Reply Notifications Allows Session Hijacking |
| CVE-2026-34358 | 8.1 HIGH | CtrlPanel: Missing Authorization on Admin Write Endpoints Allows RBAC Bypass |
| CVE-2026-34233 | 6.5 MEDIUM | CtrlPanel has Missing Authentication Checks in Datatable Admin Endpoints |
| CVE-2026-34246 | 4.8 MEDIUM | CtrlPanel: Stored XSS in Admin Role Management via Unescaped DataTable HTML Output |
No comments yet