Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 20 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ctrlpanel-gg
Ctrlpanel-gg panel |
|
| Vendors & Products |
Ctrlpanel-gg
Ctrlpanel-gg panel |
Tue, 19 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability exists in the admin role management interface. In app/Http/Controllers/Admin/RoleController.php, the datatable() method interpolates $role->name and $role->color directly into a <span> element's HTML and style attribute without sanitization, and the chained .rawColumns(['actions', 'name']) call instructs DataTables to render the name column as raw HTML, bypassing automatic output escaping. An admin with role creation or edit permissions can inject a payload such as <img src=x onerror="alert('XSS_POC')"> into the name or color fields, which is persisted to the database and executes in the browser of every admin who loads the /admin/roles page. This enables session hijacking via cookie theft, credential harvesting through fake login prompts or keyloggers, lateral privilege escalation by performing admin actions on behalf of victims, and a persistent backdoor that re-executes on every page load until the malicious role record is removed. This issue has been resolved in version 1.2.0. | |
| Title | CtrlPanel: Stored XSS in Admin Role Management via Unescaped DataTable HTML Output | |
| Weaknesses | CWE-116 CWE-80 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-20T17:21:20.034Z
Reserved: 2026-03-26T16:22:29.034Z
Link: CVE-2026-34246
Updated: 2026-05-20T17:20:44.318Z
Status : Deferred
Published: 2026-05-19T22:16:37.460
Modified: 2026-06-17T10:38:43.423
Link: CVE-2026-34246
No data.
OpenCVE Enrichment
Updated: 2026-05-20T10:38:55Z