CVE-2026-101011: aaPanel BaoTa Domain domainMod.py get_domain_status sql injection
A security flaw has been discovered in aaPanel BaoTa up to 11.8.0. This affects the function getdomainstatus of the file /www/server/panel/mod/project/domain/domainMod.py of the component Domain Handler. The manipulation of the argument get results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The affected function is remotely reachable, but the supplied CVSS vector indicates that an attacker needs high privileges. No user interaction is required.
Which installations are affected?
aaPanel BaoTa versions up to and including 11.8.0 are identified as affected. The issue is in the Domain Handler's get_domain_status function in /www/server/panel/mod/project/domain/domainMod.py.
What is the practical impact of successful exploitation?
Successful SQL injection can affect confidentiality, integrity, and availability at a low impact level, according to the supplied CVSS metrics. Public exploit information has been released, increasing the likelihood of attempted attacks.
Is a vendor fix or workaround available?
The provided information does not identify a fixed version or a vendor workaround. It states that the vendor was contacted but did not respond.