Stored Cross-Site Scripting Vulnerability in SQLBot Dashboard Component
CVE-2026-72743
Key Information:
Badges
What is CVE-2026-72743?
The SQLBot dashboard component is vulnerable to stored cross-site scripting (XSS) due to improper sanitization of user-provided content rendered through TinyMCE. This flaw allows attackers with access to modify the dashboard text widgets to inject malicious HTML and JavaScript. Consequently, any user viewing the affected dashboard can unknowingly execute these scripts, potentially compromising their session or sensitive data.
Affected Version(s)
SQLBot 0 <= 1.10.0
SQLBot 0 <= 1.10.0
SQLBot c3f40a5c05a53253b2924765b02b83f6a819948f
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
