CtrlPanel-gg是CtrlPanel-gg开源的一个易于使用且免费的计费解决方案。 CtrlPanel-gg 1.1.1及之前版本存在安全漏洞,该漏洞源于管理员角色管理界面中datatable()方法将$role->name和$role->color直接插入到<span>元素的HTML和style属性中而未进行清理,且.rawColumns([ actions , name ])调用指示DataTables将name列渲染为原始HTML,可能导致存储型跨站脚本攻击。以下版本受到影响:1.1.1及之
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Ctrlpanel-gg | panel | < 1.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ctrlpanel-gg | panel | < 1.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34234 | 10.0 CRITICAL | CtrlPanel: Unauthenticated RCE using installer script |
| CVE-2026-34241 | 8.7 HIGH | CtrlPanel: Stored XSS in Ticket Reply Notifications Allows Session Hijacking |
| CVE-2026-34358 | 8.1 HIGH | CtrlPanel: Missing Authorization on Admin Write Endpoints Allows RBAC Bypass |
| CVE-2026-34216 | 6.6 MEDIUM | CtrlPanel: Authenticated Remote Code Execution via Dynamic Class Instantiation in Settings |
| CVE-2026-34233 | 6.5 MEDIUM | CtrlPanel has Missing Authentication Checks in Datatable Admin Endpoints |
No comments yet