CyberRota Analysis
AI-GeneratedOpenpanel versions prior to 2.3.0 are vulnerable due to an insecure direct object reference in the report.getLayouts and report.resetLayout tRPC procedures, allowing authenticated attackers to manipulate dashboardId and projectId. This vulnerability enables unauthorized access to read and modify report layouts and configurations, potentially affecting multiple tenants. Organizations using Openpanel should prioritize patching this issue to safeguard their dashboard configurations and prevent data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized projectId. Authenticated attackers can supply an arbitrary victim dashboardId with their own projectId to read report layouts and configurations or delete dashboard grid arrangements across tenants.