CVE-2026-101010 aaPanel BaoTa SQL注入漏洞
影响攻击者可远程注入SQL,读取或篡改数据库数据
aaPanel BaoTa 面板 11.8.0 及之前版本中,/www/server/panel/class/data.py 文件的 getData 函数对 log_type 参数未做充分过滤,存在 SQL 注入漏洞。该漏洞可被远程利用,且利用代码已公开,厂商未作回应。
影响范围
aaPanel BaoTa 11.8.0 及更早版本,具体受影响版本范围暂无更详细的公开信息。
漏洞详情
漏洞类型为 SQL 注入。成因是 getData 函数在处理 log_type 参数时未进行安全过滤,直接将用户输入拼接到 SQL 查询中。攻击者可通过构造恶意 log_type 值远程发起注入,从而操纵数据库查询。
利用条件与风险
利用前提是攻击者能够访问面板相关接口,无需认证或低权限即可尝试。由于利用代码已公开,实战中被扫描和利用的风险较高。
修复建议
官方暂未发布修复方案,建议关注厂商更新。临时缓解措施包括限制面板访问来源、加强访问控制,或对 log_type 参数进行过滤。
A vulnerability was identified in aaPanel BaoTa up to 11.8.0. The impacted element is the function getData of the file /www/server/panel/class/data.py. The manipulation of the argument log_type leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.