CtrlPanel.gg是CtrlPanel.gg开源的一款主机服务计费管理工具。 CtrlPanel.gg 1.1.1及之前版本存在访问控制错误漏洞,该漏洞源于多个管理员控制器暴露了未授权检查的DataTable端点,允许任何经过身份验证的用户访问本应仅限于管理员的敏感管理数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ctrlpanel-gg | panel | < 1.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ctrlpanel-gg | panel | < 1.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34234 | 10.0 CRITICAL | CtrlPanel: Unauthenticated RCE using installer script |
| CVE-2026-34241 | 8.7 HIGH | CtrlPanel: Stored XSS in Ticket Reply Notifications Allows Session Hijacking |
| CVE-2026-34358 | 8.1 HIGH | CtrlPanel: Missing Authorization on Admin Write Endpoints Allows RBAC Bypass |
| CVE-2026-34216 | 6.6 MEDIUM | CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in Settings |
| CVE-2026-34246 | 4.8 MEDIUM | CtrlPanel: Stored XSS in Admin Role Management via Unescaped DataTable HTML Output |
No comments yet