Impact
The OpenPanel tracking API through version 2.3.0 fails to verify the cryptographic hash of client secrets before authorizing revenue events and bot‑filtering requests. This flaw allows an attacker who knows only the publicly exposed client ID to supply arbitrary dummy secrets, enabling the injection of forged revenue metrics and the bypass of bot detection mechanisms. The resulting unauthorized data can lead to false revenue reporting, financial fraud, and evasion of moderation controls.
Affected Systems
OpenPanel tracking API released by Openpanel-dev, versions up to and including 2.3.0. Any deployment running these versions is impacted; no additional upstream or version numbers are provided in the advisory.
Risk and Exploitability
The CVSS v3 score of 6.9 indicates moderate severity, while the EPSS score of < 1% reflects a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers need only the public client ID, which is typically disclosed, and can therefore construct a malicious request with any dummy secret over the network. Because the secret is unverified before authorizing revenue events or bot‑filtering requests, exploitation is straightforward for a remote attacker with internet access. The potential for fraudulent revenue or bot evasion is significant, especially for services that rely on the API for revenue tracking or moderation, and a lack of alerting for abnormal event patterns could permit rapid exploitation.
OpenCVE Enrichment