CyberRota Analysis
AI-GeneratedAn improper access control vulnerability in x-ui 0.3.2 allows any authenticated panel user to modify the xray configuration template, resulting in a panel restart that exposes the management gRPC service to non-loopback addresses. This misconfiguration increases the attack surface by making the management interface accessible beyond its intended local-only scope. Organizations using x-ui should prioritize this issue to prevent potential unauthorized access to sensitive management functions.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback addresses. This expands the reachable surface of the management interface beyond its intended local-only boundary.