OpenPanel Directory Traversal Vulnerability in File Manager

Vulnerability

A directory traversal vulnerability has been identified in OpenPanel versions 0.3.4 to 0.2.1. This issue allows attackers to manipulate file paths and access restricted directories through the File Manager's File Actions feature.

Impact

Exploitation of this vulnerability could lead to unauthorized access to files and directories outside the intended scope, potentially allowing sensitive information to be read or manipulated.

Reproduction

The vulnerability can be reproduced by sending crafted requests to the File Manager's File Actions endpoints. For example, the 'copy_item' endpoint can be used to traverse directories by including relative path parameters that navigate up the directory structure. Similarly, the 'view_file' endpoint can be exploited by specifying filenames and path parameters that access restricted directories.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.5
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.