Show filters
23 Total Results
Displaying 1-10 of 23
Sort by:
Attacker Value
Low
CVE-2020-9339
Disclosure Date: February 22, 2020 (last updated February 21, 2025)
SOPlanning 1.45 allows XSS via the Name or Comment to status.php.
0
Attacker Value
Very High
CVE-2020-9338
Disclosure Date: February 22, 2020 (last updated February 21, 2025)
SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.
0
Attacker Value
Low
CVE-2020-9268
Disclosure Date: February 18, 2020 (last updated February 21, 2025)
SoPlanning 1.45 is vulnerable to SQL Injection in the OrderBy clause, as demonstrated by the projets.php?order=nom_createur&by= substring.
0
Attacker Value
Low
CVE-2020-9269
Disclosure Date: February 18, 2020 (last updated February 21, 2025)
SOPlanning 1.45 is vulnerable to authenticated SQL Injection that leads to command execution via the users parameter, as demonstrated by export_ical.php.
0
Attacker Value
Very Low
CVE-2020-9266
Disclosure Date: February 18, 2020 (last updated February 21, 2025)
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
0
Attacker Value
Unknown
CVE-2024-9574
Disclosure Date: October 07, 2024 (last updated October 09, 2024)
SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.
0
Attacker Value
Unknown
CVE-2024-9573
Disclosure Date: October 07, 2024 (last updated October 09, 2024)
SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which could allow a remote user to send a specially crafted query and extract all the information stored on the server.
0
Attacker Value
Unknown
CVE-2024-9572
Disclosure Date: October 07, 2024 (last updated October 09, 2024)
Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/groupe_save.php, in the groupe_id parameter. This could allow a remote user to send a specially crafted query to an authenticated user and steal their session details.
0
Attacker Value
Unknown
CVE-2024-9571
Disclosure Date: October 07, 2024 (last updated October 09, 2024)
Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/xajax_server.php, affecting multiple parameters. This could allow a remote user to send a specially crafted query to an authenticated user and partially take control of their browser session.
0
Attacker Value
Unknown
CVE-2024-27115
Disclosure Date: September 11, 2024 (last updated September 19, 2024)
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any requirements. This leads to the possibility of execution of code on the underlying system when the file is triggered. The vulnerability has been remediated in version 1.52.02.
0