CyberRota Analysis
AI-GeneratedOpenPanel versions prior to 2.3.0 are vulnerable to a cross-site scripting (XSS) flaw in the unauthenticated favicon proxy endpoint, allowing remote attackers to execute scripts via malicious SVG file URLs. This vulnerability can lead to unauthorized access to authenticated endpoints by leveraging same-origin credentialed requests in victims' browsers. Organizations using OpenPanel should prioritize patching this issue to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicious SVG files with embedded scripts that execute in the victim's browser on the API origin, enabling same-origin credentialed requests to authenticated endpoints.