CVE-2026-41472

CyberPanel: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CVE-2026-41472)

Beschreibung

CyberPanel-Versionen vor 2.4.4 enthalten eine persistente Cross-Site-Scripting-Anfälligkeit im AI Scanner-Dashboard, bei der die POST /api/ai-scanner/callback-Endpunkt keine Authentifizierung erfordert und es unauthentifizierten Angreifern ermöglicht, schädlichen JavaScript-Code einzuschleusen, indem sie das findings_json-Feld von ScanHistory-Einträgen überschreiben. Angreifer können JavaScript einfügen, der in einer authentifizierten Sitzung eines Administrators ausgeführt wird, wenn dieser das AI Scanner-Dashboard besucht, wodurch sie Anfragen im gleichen Ursprung platzieren und Cron-Jobs auf dem Server einrichten sowie eine Fernausführung von Code erreichen können.

Metriken

Severity
medium
PoC (öffentlich gemeldet)
6.1
Quelle: nvd-v3
42.3 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.5 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-04-24 20:40 UTC
CWE-79

Weakness-Klassen (CWE)

  • CWE-79Base

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-08-11 18:17 UTC· disclosure@vulncheck.com
    • Affected: cyberpanelcyberpanel
    • Description: CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanHistory records. Attackers can inject JavaScript that executes in an administrator's authenticated session when they visit the AI Scanner dashboard, allowing them to issue same-origin requests to plant cron jobs and achieve remote code execution on the server.CyberPanel versions prior to 2.4.5 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanHistory records. Attackers can inject JavaScript that executes in an administrator's authenticated session when they visit the AI Scanner dashboard, allowing them to issue same-origin requests to plant cron jobs and achieve remote code execution on the server.
    • Reference: https://github.com/usmannasir/cyberpanel/commit/8eb29181cb137baa4adb4bba5dce60f601d55a5f
    • Reference: https://github.com/usmannasir/cyberpanel/commit/0a099b1b193946555fbdd387a28486b1521f9961

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Open Source

    CyberPanel< 2.4.4

    gefixt in 2.4.4

Quellen & Referenzen

IDCVE-2026-41472