← Zurück zur CVE-Suche

CVE-2026-34241

CtrlPanel

Beschreibung

CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability in the ticket reply notification system. Unsanitized reply content ($newmessage) is stored directly in database notification payloads and later rendered unescaped via Blade-s {!! !!} syntax in the recipient-s browser. The flaw exists in both AppNotificationsTicketAdminAdminReplyNotification (triggered when a user replies, targeting admins) and AppNotificationsTicketUserReplyNotification (triggered when an admin replies, targeting users), allowing arbitrary JavaScript execution in the victim-s session context. A low-privileged attacker can exploit this to hijack admin sessions, harvest credentials via fake login prompts or keyloggers, and escalate privileges by performing administrative actions on the victim-s behalf. The reverse path also enables a malicious or compromised admin to target regular users in the same manner. This issue has been fixed in version 1.2.0.

CVSS 8.7EPSS 0.349%Risiko 0.9
Quelle öffnen
Veröffentlicht
2026-05-19 22:16:37
Betroffene Versionen
<1.1.2
Typ
Core software
Zuletzt geändert
2026-07-24 09:10:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N