Executive brief
stilleshan ServerStatus is a server monitoring and statistics tool that generates performance reports. A vulnerability allows attackers to inject malicious scripts into the custom parameter, which are then executed when the report is viewed—potentially enabling account takeover, session hijacking, or data theft from affected administrators.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw in the Stats Generation component of stilleshan ServerStatus, specifically triggered through manipulation of the 'custom' argument in an unknown function within server/src/main.cpp. The attack is remotely exploitable with no authentication required, allowing an attacker to inject arbitrary JavaScript that executes in the context of an administrator's browser. Public exploit code is available, and the vendor has not responded to disclosure attempts. A patch status is unknown.
Affected products
- stilleshan ServerStatus 1.0/2.0
Timeline
- 2026-09-13: disclosed
- other: Public exploit code made available