Openpanel

Openpanel

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 21.08.2026 11:05:15
  • Zuletzt bearbeitet 21.08.2026 11:17:07

The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc/src/trpc.ts verified membership for the supplied ...

  • EPSS 0.24%
  • Veröffentlicht 21.08.2026 11:05:14
  • Zuletzt bearbeitet 21.08.2026 18:16:52

The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evaluates membership only when the input carries a proje...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 14.03.2025 00:00:00
  • Zuletzt bearbeitet 03.04.2025 15:35:07

An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function

Exploit
  • EPSS 0.44%
  • Veröffentlicht 14.03.2025 00:00:00
  • Zuletzt bearbeitet 03.04.2025 15:36:00

An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function

Exploit
  • EPSS 4.11%
  • Veröffentlicht 31.01.2025 17:15:15
  • Zuletzt bearbeitet 23.05.2025 15:57:32

OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.

Exploit
  • EPSS 3.2%
  • Veröffentlicht 31.01.2025 16:15:35
  • Zuletzt bearbeitet 23.05.2025 15:58:50

An issue found in the Copy and View functions in the File Manager component of OpenPanel v0.3.4 allows attackers to execute a directory traversal via a crafted HTTP request.

  • EPSS 2.32%
  • Veröffentlicht 31.01.2025 16:15:34
  • Zuletzt bearbeitet 02.10.2025 18:32:08

An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager.