vendor:
OpenPanel
by:
Korn Chaisuwan, Punthat Siriwan, Pongtorn Angsuchotmetee
6.1
CVSS
HIGH
Incorrect Access Control
284
CWE
Product Name: OpenPanel
Affected Version From: 2000.3.4
Affected Version To: 2000.3.4
Patch Exists: NO
Related CWE: CVE-2024-53582
CPE: a:openpanel:openpanel:0.3.4
Platforms Tested: macOS
2024
OpenPanel 0.3.4 – Incorrect Access Control
The OpenPanel version 0.3.4 is vulnerable to an incorrect access control issue. An attacker can exploit this vulnerability by sending a crafted HTTP request to access unauthorized files or directories on the server.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of OpenPanel that addresses the access control issue. Additionally, restricting access to the server and implementing proper authorization mechanisms can help prevent unauthorized access.