vendor:
OpenPanel
by:
Korn Chaisuwan, Punthat Siriwan, Pongtorn Angsuchotmetee
6.1
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: OpenPanel
Affected Version From: 4.3
Affected Version To: 2000.3.4
Patch Exists: NO
Related CWE: CVE-2024-53537
CPE: a:openpanel:openpanel:0.3.4
Platforms Tested: macOS
2024
OpenPanel 0.3.4 – Directory Traversal
The OpenPanel version 0.3.4 is vulnerable to directory traversal. By exploiting this vulnerability, an attacker can traverse the directories outside the intended location and gain unauthorized access to sensitive files. This vulnerability has been assigned CVE-2024-53537.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of OpenPanel that addresses the directory traversal issue. Additionally, access controls and input validation mechanisms should be implemented to restrict unauthorized access.