Soplanning

Soplanning

34 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.84%
  • Veröffentlicht 18.03.2025 00:00:00
  • Zuletzt bearbeitet 02.04.2025 12:29:33

A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to bypass upload restrictions and potentially achieve remote code execution by uploading malicious files.

  • EPSS 0.19%
  • Veröffentlicht 07.10.2024 15:15:10
  • Zuletzt bearbeitet 08.10.2024 18:45:13

SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

  • EPSS 0.09%
  • Veröffentlicht 07.10.2024 15:15:10
  • Zuletzt bearbeitet 08.10.2024 18:45:09

SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which could allow a remote user to send a specially crafted query and extract all the information stored on the server.

  • EPSS 0.1%
  • Veröffentlicht 07.10.2024 15:15:09
  • Zuletzt bearbeitet 08.10.2024 18:45:03

Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/groupe_save.php, in the groupe_id parameter. This could allow a remote user to send a specially crafted query to ...

  • EPSS 0.11%
  • Veröffentlicht 07.10.2024 15:15:09
  • Zuletzt bearbeitet 08.10.2024 18:45:01

Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/xajax_server.php, affecting multiple parameters. This could allow a remote user to send a specially crafted query...

  • EPSS 1.82%
  • Veröffentlicht 11.09.2024 14:15:13
  • Zuletzt bearbeitet 19.09.2024 14:27:11

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before i...

  • EPSS 80.37%
  • Veröffentlicht 11.09.2024 14:15:13
  • Zuletzt bearbeitet 18.09.2024 20:32:26

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any require...

  • EPSS 0.17%
  • Veröffentlicht 11.09.2024 14:15:12
  • Zuletzt bearbeitet 18.09.2024 18:43:00

An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database ...

  • EPSS 0.22%
  • Veröffentlicht 11.09.2024 14:15:12
  • Zuletzt bearbeitet 18.09.2024 18:42:19

A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database. The vulnerability has been remediated in v...

  • EPSS 0.54%
  • Veröffentlicht 21.03.2021 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:02:15

SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation code, and there is no key for publicsp (which is a gue...