CNNVD-202601-2949 Information
Jan 18, 2026
cve
CNNVD ID
CNNVD-202601-2949
Related CVE
- CNNVD Published: 2026-01-18
Description (Chinese)
1Panel是中国1Panel社区的一个开源的Linux服务器运维管理面板。 1Panel v1.10.33-lts及之前版本和v2.0.16及之前版本存在跨站脚本漏洞,该漏洞源于MdEditor组件在启用previewOnly属性时内容清理不足,可能导致存储型跨站脚本攻击。
Description (English)
1 Panel is an open-source Linux server management panel for a Panel community in China. 1 Panel v1.10.33-lts and previous and v2.0.16 and previous versions have a cross-site script loophole, which stems from the fact that the MdEditor component was inadequately cleaned when it enabled the PreviewOnly properties and could result in a storage-type cross-site script attack.
Hazard Level
High
Vulnerability Type
跨站脚本
Affected Vendor
1Panel
Published
2026-01-18
Last Modified
2026-02-24
References
https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-mg24-6h5c-9q42 https://access.redhat.com/security/cve/cve-2026-23525
Patch
https://github.com/1Panel-dev/1Panel/releases
Share on: