CVE-2026-77769
- EPSS 0.24%
- Veröffentlicht 21.08.2026 11:05:15
- Zuletzt bearbeitet 21.08.2026 11:17:07
The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc/src/trpc.ts verified membership for the supplied ...
CVE-2026-77768
- EPSS 0.24%
- Veröffentlicht 21.08.2026 11:05:14
- Zuletzt bearbeitet 21.08.2026 18:16:52
The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evaluates membership only when the input carries a proje...
CVE-2025-25872
- EPSS 0.26%
- Veröffentlicht 14.03.2025 00:00:00
- Zuletzt bearbeitet 03.04.2025 15:35:07
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function
- EPSS 0.44%
- Veröffentlicht 14.03.2025 00:00:00
- Zuletzt bearbeitet 03.04.2025 15:36:00
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function
CVE-2024-53584
- EPSS 4.11%
- Veröffentlicht 31.01.2025 17:15:15
- Zuletzt bearbeitet 23.05.2025 15:57:32
OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.
CVE-2024-53582
- EPSS 3.2%
- Veröffentlicht 31.01.2025 16:15:35
- Zuletzt bearbeitet 23.05.2025 15:58:50
An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to execute a directory traversal via a crafted HTTP request.
CVE-2024-53537
- EPSS 2.32%
- Veröffentlicht 31.01.2025 16:15:34
- Zuletzt bearbeitet 02.10.2025 18:32:08
An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager.