PT-2020-10360 · Soplanning · Soplanning

Published

2020-01-09

·

Updated

2020-01-15

·

CVE-2019-20179

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SOPlanning version 1.45
Description The issue is related to SQL injection, which can be exploited via the user list.php API endpoint, specifically through the by parameter.
Recommendations For SOPlanning version 1.45, avoid using the by parameter in the user list.php endpoint until the issue is resolved. Consider restricting access to this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20179

Affected Products

Soplanning