Sceawere
Vulnerability Detail
CVE-2026-101010UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
aaPanel SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 4h ago
- Vendor
- aaPanel
- Product
- BaoTa
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in aaPanel BaoTa up to 11.8.0. The impacted element is the function getData of the file /www/server/panel/class/data.py. The manipulation of the argument log_type leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-09-28T08:16:36.807Z",
"pubdate": "2026-09-28T08:16:36.807Z",
"executiveSummary": "A SQL injection vulnerability has been identified in aaPanel (BaoTa) versions up to 11.8.0. The vulnerability exists within the 'getData' function located in '/www/server/panel/class/data.py'.\nThe flaw stems from improper neutralization of the 'log_type' argument, allowing an unauthenticated or authenticated remote attacker to manipulate database queries.\nSuccessful exploitation permits unauthorized access to the underlying database, potentially leading to data exfiltration, modification, or complete compromise of the hosting environment.\nGiven that public exploit code is available and the vendor has remained unresponsive, this vulnerability poses a significant risk to the integrity and confidentiality of affected aaPanel installations.\nImmediate action is required to isolate affected systems or implement network-level filtering to prevent exploitation attempts.",
"technicalDetails": "The vulnerability is situated in the 'getData' function within the '/www/server/panel/class/data.py' file. The root cause is the insecure handling of the 'log_type' input parameter, which is incorporated directly into SQL query construction without adequate sanitization, input validation, or the use of parameterized queries.\nThe attack flow initiates with a remote request sent to the aaPanel management interface where the 'log_type' parameter is manipulated by an attacker to include arbitrary SQL syntax. Because the application logic fails to employ prepared statements, the database engine interprets the malicious input as part of the executable command.\nBy leveraging this flaw, an attacker can perform a variety of operations including 'UNION'-based SQL injection to extract sensitive information from the database, such as system configurations, administrative credentials, or hosted website data. Furthermore, depending on the database user permissions and backend configuration, an attacker may be able to execute administrative functions or escalate privileges within the application environment.\nThis vulnerability is accessible remotely over the network, allowing attackers to compromise the server without prior authentication, depending on the specific configuration of the panel. The lack of proper input filtering on the server-side code ensures that the database driver receives untrusted, non-sanitized strings, which are then processed by the underlying SQL engine.\nThe impact of a successful injection goes beyond simple data retrieval. In environments where the database user has elevated system privileges, the exploit could potentially be utilized for file-based operations or to manipulate system logs, allowing the attacker to establish persistence or facilitate further lateral movement within the compromised server infrastructure. As of the current assessment, the absence of vendor-supplied patches means that the codebase remains inherently susceptible to this vector."
}