CVE-2025-62731
- EPSS 0.04%
- Veröffentlicht 20.11.2025 15:44:17
- Zuletzt bearbeitet 24.11.2025 13:53:27
SOPlanning is vulnerable to Stored XSS in /feries endpoint. Malicious attacker with access to public holidays feature is able to inject arbitrary HTML and JS into website, which will be rendered/executed when opening multiple pages. By default only a...
CVE-2025-62730
- EPSS 0.05%
- Veröffentlicht 20.11.2025 15:44:09
- Zuletzt bearbeitet 24.11.2025 13:53:07
SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This a...
CVE-2025-62729
- EPSS 0.04%
- Veröffentlicht 20.11.2025 15:43:59
- Zuletzt bearbeitet 24.11.2025 13:52:24
SOPlanning is vulnerable to Stored XSS in /status endpoint. Malicious attacker with an account can inject arbitrary HTML and JS into website, which will be rendered/executed when opening multiple pages. This issue was fixed in version 1.55.
CVE-2025-62297
- EPSS 0.04%
- Veröffentlicht 20.11.2025 15:43:56
- Zuletzt bearbeitet 24.11.2025 13:52:15
SOPlanning is vulnerable to Stored XSS in /projets endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening edited page. This issue was fixed in version 1.55.
CVE-2025-62296
- EPSS 0.04%
- Veröffentlicht 20.11.2025 15:43:51
- Zuletzt bearbeitet 24.11.2025 13:52:06
SOPlanning is vulnerable to Stored XSS in /taches endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening editor. This issue was fixed in version 1.55.
CVE-2025-62295
- EPSS 0.04%
- Veröffentlicht 20.11.2025 15:43:45
- Zuletzt bearbeitet 24.11.2025 13:51:56
SOPlanning is vulnerable to Stored XSS in /groupe_form endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening editor. This issue was fixed in version 1.55.
CVE-2025-62294
- EPSS 0.05%
- Veröffentlicht 20.11.2025 15:43:40
- Zuletzt bearbeitet 24.11.2025 13:51:22
SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recovery tokens, a malicious attacker is able to brute-force all possible values and takeover any account in reasonable amount of time....
CVE-2025-62293
- EPSS 0.04%
- Veröffentlicht 20.11.2025 15:43:30
- Zuletzt bearbeitet 24.11.2025 13:44:41
SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Status functionality an authenticated attacker is able to add, edit and delete any status. This issue was fixed in version 1.55.
CVE-2025-41001
- EPSS 0.05%
- Veröffentlicht 10.11.2025 09:57:40
- Zuletzt bearbeitet 21.11.2025 21:17:53
Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'LOGOUT_REDIRECT' parameter in '/soplanning/www/process/options...
CVE-2024-57170
- EPSS 0.53%
- Veröffentlicht 18.03.2025 00:00:00
- Zuletzt bearbeitet 02.04.2025 12:29:14
SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attackers to specify file paths containing directory traversal sequences (e.g., ../). This vulnerability en...