GHSA-6vg6-383g-xj2wHighCVSS 8.5
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter...
🔗 CVE IDs covered (1)
📋 Description
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques.