Impact
The vulnerability allows an authenticated member of an OpenReplay enterprise installation with multi‑tenancy enabled to supply crafted input that is embedded directly into ClickHouse queries without proper escaping. This flaw can be exploited to read arbitrary ClickHouse tables through blind boolean and time‑based exfiltration and can also disable the session‑search functionality for all viewers until the stored key used in the query is removed.
Affected Systems
OpenReplay, a self‑hosted session replay suite, enterprise editions with multi‑tenancy enabled, before release 1.27.0. All installed versions older than 1.27.0 are affected, while 1.27.0 and later contain a fix that sanitises user input before query construction.
Risk and Exploitability
The CVSS score is 5.4, indicating a medium severity vulnerability. The EPSS score is <1% ( very low exploitation probability, and the vulnerability is not listed in CISA KEV, suggesting a moderate exploitation risk. Based on the description, the likely attack vector is internal and requires authenticated access within the OpenReplay system; attackers would need valid authenticated access to exploit the flaw, implying that compromised credentials or weak user management can lead to data exfiltration. Once authenticated, an attacker can extract sensitive data from any ClickHouse table and potentially disrupt session‑search functionality, impacting availability as well.
OpenCVE Enrichment