Impact
OpenPanel through version 2.3.0 does not escape property keys in ClickHouse SQL queries, which allows an authenticated user to inject boolean SQL terms. Attackers can supply crafted filter names to bypass the standard project isolation logic, granting them read access to metrics from projects they should not normally be able to view. This flaw is a classic SQL injection vulnerability (CWE‑89) that permits unauthorized access to project‑specific data.
Affected Systems
The affected product is Openpanel-dev's OpenPanel application. Versions up to and including 2.3.0 are affected, and no specific version range beyond that is identified in the advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score is < 1%, implying a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting it is not presently known to be actively exploited. The attack vector requires an authenticated user with access to the web interface that accepts property key filters. Once authenticated, the attacker can craft a filter name that injects boolean SQL, thereby retrieving metrics from other projects. This promotes unauthorized data disclosure with limited operational impact beyond visibility.
OpenCVE Enrichment