Cross Site Scripting Vulnerability in cym1102 nginxWebUI Affected by Web Management Interface
CVE-2026-2145
Key Information:
- Vendor
Cym1102
- Status
- Vendor
- CVE Published:
- 8 February 2026
Badges
What is CVE-2026-2145?
A critical flaw was discovered in the cym1102 nginxWebUI prior to version 4.3.7, where an unknown function within the Web Management Interface's configuration file allows attackers to inject malicious scripts. This vulnerability can be exploited remotely by manipulating the 'nginxDir' argument, leading to potential cross site scripting attacks. With known exploits publicly available and a lack of response from the developers following an early issue report, users are urged to take immediate action to mitigate risks.
Affected Version(s)
nginxWebUI 4.3.0
nginxWebUI 4.3.1
nginxWebUI 4.3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
