PT-2020-7755 · Unknown · Soplanning

Huy-Ngoc Dau

·

Published

2020-01-06

·

Updated

2020-01-10

·

CVE-2014-8674

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SOPlanning versions prior to 1.33
Description The issue concerns multiple Cross-Site Scripting (XSS) vulnerabilities. These vulnerabilities allow malicious users to execute arbitrary code via the document.cookie in nb mois and mb ligness and the debug GET parameter to "export.php".
Recommendations For versions prior to 1.33, update to version 1.33 or later to resolve the issue. As a temporary workaround, consider restricting access to the "export.php" endpoint and avoiding the use of the debug GET parameter until a patch is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8674

Affected Products

Soplanning