Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown
CVE-2024-27114
Disclosure Date: September 11, 2024 (last updated September 20, 2024)
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is removed, leading to execution of code on the underlying system. The vulnerability has been remediated in version 1.52.02.
0
Attacker Value
Unknown
CVE-2024-27113
Disclosure Date: September 11, 2024 (last updated September 19, 2024)
An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database by exporting it as a CSV file. The vulnerability has been remediated in version 1.52.02.
0
Attacker Value
Unknown
CVE-2024-27112
Disclosure Date: September 11, 2024 (last updated September 19, 2024)
A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database. The vulnerability has been remediated in version 1.52.02.
0
Attacker Value
Unknown
CVE-2020-13963
Disclosure Date: March 21, 2021 (last updated November 28, 2024)
SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation code, and there is no key for publicsp (which is a guest account).
0
Attacker Value
Unknown
CVE-2020-25867
Disclosure Date: October 07, 2020 (last updated February 22, 2025)
SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentication.
0
Attacker Value
Unknown
CVE-2020-15597
Disclosure Date: August 11, 2020 (last updated February 21, 2025)
SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment field.
0
Attacker Value
Unknown
CVE-2020-9267
Disclosure Date: February 18, 2020 (last updated February 21, 2025)
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
0
Attacker Value
Unknown
CVE-2014-8673
Disclosure Date: January 07, 2020 (last updated February 21, 2025)
Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33.
0
Attacker Value
Unknown
CVE-2014-8674
Disclosure Date: January 06, 2020 (last updated February 21, 2025)
Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET parameter to export.php, which allows malicious users to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2019-20179
Disclosure Date: June 19, 2019 (last updated February 21, 2025)
SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.
0