CVE-2026-101011 aaPanel BaoTa Domain Handler SQL注入漏洞
影响攻击者可远程注入SQL语句,可能读取或篡改数据库数据
aaPanel BaoTa 面板的 Domain Handler 组件中,domainMod.py 文件的 get_domain_status 函数存在 SQL 注入漏洞。攻击者可远程利用该漏洞操纵参数执行注入攻击,且利用代码已公开。厂商已被告知但未作回应。
影响范围
aaPanel BaoTa 11.8.0 及更早版本(up to 11.8.0),具体受影响版本范围以官方公告为准,暂无公开信息。
漏洞详情
漏洞类型为 SQL 注入,位于 /www/server/panel/mod/project/domain/domainMod.py 的 get_domain_status 函数。该函数未对传入参数进行充分过滤或参数化处理,导致攻击者可构造恶意输入拼接进 SQL 查询。攻击者可远程发送特制请求触发注入,进而操纵数据库查询。
利用条件与风险
利用前提是目标面板相关接口可被远程访问,且攻击者能控制传入参数。由于利用代码已公开,实战中被扫描和攻击的风险较高,但 CVSS 4.7 属中危,具体危害取决于数据库权限与部署环境。
修复建议
官方暂未发布修复方案,建议关注 aaPanel 官方更新并及时升级。临时缓解措施包括限制面板访问来源、启用强认证、在边界设备上过滤恶意请求,或在不影响业务的前提下禁用相关接口。
A security flaw has been discovered in aaPanel BaoTa up to 11.8.0. This affects the function get_domain_status of the file /www/server/panel/mod/project/domain/domainMod.py of the component Domain Handler. The manipulation of the argument get results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.