Περιγραφή
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability in the ticket reply notification system. Unsanitized reply content ($newmessage) is stored directly in database notification payloads and later rendered unescaped via Blade-s {!! !!} syntax in the recipient-s browser. The flaw exists in both AppNotificationsTicketAdminAdminReplyNotification (triggered when a user replies, targeting admins) and AppNotificationsTicketUserReplyNotification (triggered when an admin replies, targeting users), allowing arbitrary JavaScript execution in the victim-s session context. A low-privileged attacker can exploit this to hijack admin sessions, harvest credentials via fake login prompts or keyloggers, and escalate privileges by performing administrative actions on the victim-s behalf. The reverse path also enables a malicious or compromised admin to target regular users in the same manner. This issue has been fixed in version 1.2.0.
- Δημοσίευση
- 2026-05-19 22:16:37
- Επηρεαζόμενες εκδόσεις
- <1.1.2
- Τύπος
- Core software
- Τελευταία τροποποίηση
- 2026-07-24 09:10:00
- Διάνυσμα
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N