Search
Search Results (5 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-79315 | 1 Vaxilu | 1 X-ui | 2026-09-22 | 4.7 Medium |
| A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for sidebar menu highlighting. Server-side HTML entity escaping is ineffective in this context: the browser decodes the entities before the client-side framework evaluates the content as a JavaScript expression. A logged-in panel user who visits a crafted URL allows arbitrary script execution in the same-origin context of the management page, enabling data theft and unauthorized actions through the victim's session. | ||||
| CVE-2026-79316 | 1 Vaxilu | 1 X-ui | 2026-09-22 | 7.6 High |
| An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback addresses. This expands the reachable surface of the management interface beyond its intended local-only boundary. | ||||
| CVE-2026-79317 | 1 Vaxilu | 1 X-ui | 2026-09-22 | 4.8 Medium |
| A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and authentication only checks that a user object can be retrieved from the cookie without re-validating against the database or any session version. When an administrator changes the username or password, previously issued session cookies are not revoked, so an attacker who holds a pre-change admin cookie can continue accessing and operating the management interface after the credentials have been rotated. | ||||
| CVE-2026-79314 | 1 Vaxilu | 1 X-ui | 2026-09-22 | N/A |
| A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry time and traffic quota, by submitting a request referencing the target resource identifier. The update path fails to verify that the target resource belongs to the requesting session user, allowing unauthorized cross-user modification of data. | ||||
| CVE-2023-41595 | 1 Vaxilu | 1 X-ui | 2024-11-21 | 7.5 High |
| An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password. | ||||
Page 1 of 1.