Impact
The vulnerability resides in the InputSql function of aaPanel BaoTa's database backup handler. An attacker can manipulate the Password argument to inject arbitrary shell commands, resulting in remote command execution with the privileges of the web server process. This flaw is a classic OS command injection (CWE-77, CWE-78). Because the functionality can be triggered remotely via a crafted HTTP request, an attacker could compromise the host without needing local access.
Affected Systems
Affected vendors: aaPanel for its BaoTa control panel. Any installation at or before version 11.8.0 of aaPanel BaoTa is vulnerable. The database backup feature (class/database.py) processes the Password parameter unsafely. All customers running the affected releases and relying on the backup module are at risk.
Risk and Exploitability
CVSS score 9.3 signifies critical severity, indicating high impact and ease of exploitation. EPSS is not available, but the public disclosure and vendor unresponsiveness suggest the risk is real and likely. The vulnerability can be exercised by sending a crafted request to the backup endpoint; the stack trace shows the direct use of the Password argument in an os.exec call. The flaw is not limited to local users, so the attack vector is remote and traffic can be intercepted from the network. Because the flaw runs in the web process, successful exploitation results in persistent compromise of the host.
OpenCVE Enrichment