Sceawere
Vulnerability Detail
CVE-2026-101011UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
aaPanel SQL Injection Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 4h ago
- Vendor
- aaPanel
- Product
- BaoTa
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in aaPanel BaoTa up to 11.8.0. This affects the function get_domain_status of the file /www/server/panel/mod/project/domain/domainMod.py of the component Domain Handler. The manipulation of the argument get results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-09-28T08:16:36.980Z",
"pubdate": "2026-09-28T08:16:36.980Z",
"executiveSummary": "A critical SQL injection vulnerability has been identified in the Domain Handler component of aaPanel (BaoTa), affecting all versions up to 11.8.0. The vulnerability stems from improper neutralization of user-supplied input within the 'get_domain_status' function located in '/www/server/panel/mod/project/domain/domainMod.py'.\nThis flaw allows remote, unauthenticated attackers to manipulate database queries by injecting malicious SQL commands via the 'get' argument. Successful exploitation grants an attacker the ability to interact directly with the underlying database, potentially leading to unauthorized data exfiltration, modification of administrative records, or full compromise of the database integrity.\nGiven that proof-of-concept exploit code is publicly available and the vendor has not provided a response or corrective patch, the risk level is high. Organizations utilizing affected aaPanel versions are exposed to severe security threats, as the vulnerability facilitates remote exploitation without the necessity of prior authentication, enabling complete control over the panel's backend data store.",
"technicalDetails": "The vulnerability is situated in the 'get_domain_status' function within the 'domainMod.py' module, which is part of the aaPanel Domain Handler component. The root cause of this security flaw is the failure to implement parameterized queries or adequate input sanitization when processing the 'get' parameter. By failing to filter or escape the input before concatenating it into a SQL statement, the application becomes susceptible to arbitrary SQL code execution.\nThe attack flow begins with the adversary targeting the specific endpoint that invokes the 'get_domain_status' function. An attacker transmits a crafted HTTP request containing a malicious payload within the 'get' parameter. Because the application logic treats this input as a trusted value within the database query string, the injected SQL commands are executed with the privileges of the database user configured for the aaPanel instance.\nThe injection mechanism allows for blind or time-based SQL injection, enabling the attacker to infer the structure of the database, enumerate table names, dump user credentials, or modify existing domain configurations. Because the component is reachable over the network, this vulnerability is classified as remotely exploitable. The lack of input validation at the function level means the application fails to distinguish between legitimate domain status identifiers and malicious SQL syntax commands.\nThe post-exploitation impact is severe. An attacker can leverage this access to perform lateral movement within the system, achieve unauthorized data access, or escalate privileges by manipulating user accounts or API keys stored in the database. Furthermore, if the database user possesses elevated permissions, the attacker could theoretically execute system-level commands or cause a denial of service (DoS) by dropping tables or locking the database.\nThe vulnerability affects all versions of aaPanel up to and including 11.8.0. There is no requirement for session authentication to trigger the vulnerable code path, as the endpoint is exposed to public network access. Technical analysis of the public exploit indicates that the payload successfully breaks the intended SQL context, allowing for the injection of UNION-based queries or logical operators to bypass existing security filters."
}