Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown

CVE-2024-27114

Disclosure Date: September 11, 2024 (last updated September 20, 2024)
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is removed, leading to execution of code on the underlying system. The vulnerability has been remediated in version 1.52.02.
Attacker Value
Unknown

CVE-2024-27113

Disclosure Date: September 11, 2024 (last updated September 19, 2024)
An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database by exporting it as a CSV file. The vulnerability has been remediated in version 1.52.02.
Attacker Value
Unknown

CVE-2024-27112

Disclosure Date: September 11, 2024 (last updated September 19, 2024)
A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database. The vulnerability has been remediated in version 1.52.02.
Attacker Value
Unknown

CVE-2020-13963

Disclosure Date: March 21, 2021 (last updated November 28, 2024)
SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation code, and there is no key for publicsp (which is a guest account).
Attacker Value
Unknown

CVE-2020-25867

Disclosure Date: October 07, 2020 (last updated February 22, 2025)
SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentication.
Attacker Value
Unknown

CVE-2020-15597

Disclosure Date: August 11, 2020 (last updated February 21, 2025)
SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment field.
Attacker Value
Unknown

CVE-2020-9267

Disclosure Date: February 18, 2020 (last updated February 21, 2025)
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
Attacker Value
Unknown

CVE-2014-8673

Disclosure Date: January 07, 2020 (last updated February 21, 2025)
Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33.
Attacker Value
Unknown

CVE-2014-8674

Disclosure Date: January 06, 2020 (last updated February 21, 2025)
Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET parameter to export.php, which allows malicious users to execute arbitrary code.
Attacker Value
Unknown

CVE-2019-20179

Disclosure Date: June 19, 2019 (last updated February 21, 2025)
SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.