Impact
This vulnerability allows an authenticated attacker to read and delete cross‑tenant dashboard layouts by calling the report.getLayouts and report.resetLayout procedures. The failure to restrict database queries to the caller’s project lets the attacker supply a project identifier they do not own, enabling them to access confidential report definitions or permanently delete layouts. The weakness in object‑level authorization means the attacker ends up with data confidentiality breaches and integrity damage, but does not provide arbitrary code execution or denial of service.
Affected Systems
OpenPanel versions prior to 2.3.0 are vulnerable. The affected product is OpenPanel from Openpanel‑dev. No specific sub‑versions are listed beyond the cutoff at 2.3.0.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity risk. EPSS is not available, so the likelihood of exploitation in the wild is uncertain. The vulnerability is not listed in the CISA KEV catalog, and no publicly disclosed exploits are known. The attack requires the attacker to be an authenticated user in the system, which limits the target surface, but an internal actor or compromised account could exploit it to read or delete dashboards across tenants. The scope is limited to the application’s data tier, and the impact is confined to confidentiality and integrity of dashboard data.
OpenCVE Enrichment