CVE-2026-41472
CyberPanel: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CVE-2026-41472)
Beschreibung
CyberPanel-Versionen vor 2.4.4 enthalten eine persistente Cross-Site-Scripting-Anfälligkeit im AI Scanner-Dashboard, bei der die POST /api/ai-scanner/callback-Endpunkt keine Authentifizierung erfordert und es unauthentifizierten Angreifern ermöglicht, schädlichen JavaScript-Code einzuschleusen, indem sie das findings_json-Feld von ScanHistory-Einträgen überschreiben. Angreifer können JavaScript einfügen, der in einer authentifizierten Sitzung eines Administrators ausgeführt wird, wenn dieser das AI Scanner-Dashboard besucht, wodurch sie Anfragen im gleichen Ursprung platzieren und Cron-Jobs auf dem Server einrichten sowie eine Fernausführung von Code erreichen können.
Metriken
Weakness-Klassen (CWE)
CWE-79Base
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-08-11 18:17 UTC· disclosure@vulncheck.com
- Affected: cyberpanel → cyberpanel
- Description: CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanHistory records. Attackers can inject JavaScript that executes in an administrator's authenticated session when they visit the AI Scanner dashboard, allowing them to issue same-origin requests to plant cron jobs and achieve remote code execution on the server. → CyberPanel versions prior to 2.4.5 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScript by overwriting the findings_json field of ScanHistory records. Attackers can inject JavaScript that executes in an administrator's authenticated session when they visit the AI Scanner dashboard, allowing them to issue same-origin requests to plant cron jobs and achieve remote code execution on the server.
- Reference: https://github.com/usmannasir/cyberpanel/commit/8eb29181cb137baa4adb4bba5dce60f601d55a5f
- Reference: https://github.com/usmannasir/cyberpanel/commit/0a099b1b193946555fbdd387a28486b1521f9961
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
Open Source
CyberPanel< 2.4.4
gefixt in 2.4.4