Executive brief
oPanel is a control panel used to manage hosting, DNS, and domain services. A cross-site scripting (XSS) vulnerability in its DNS lookup and management component allows attackers to inject malicious JavaScript code through crafted DNS TXT records. When administrators or users interact with affected DNS records, the injected code executes in their browser, potentially leading to session hijacking, credential theft, and unauthorized access to the control panel.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in the DNS lookup/management component of oPanel that occurs when user input from DNS TXT records is not properly sanitized before being rendered in the web interface. An attacker can craft a malicious DNS TXT record containing JavaScript payloads; when the DNS management interface displays or processes this record, the script executes in the context of the logged-in user's browser. This allows attackers to hijack user sessions, steal authentication tokens, or perform unauthorized administrative actions. The vulnerability affects oPanel versions before 1.20.25 and requires no special privileges to create a malicious DNS record. A patch is available in version 1.20.25 and later.
Affected products
- <UNKNOWN> oPanel before 1.20.25
Timeline
- 2026-08-28: disclosed