PT-2024-21655 · Unknown · So Planning Tool
Hidde Smit
+1
·
Published
2024-09-11
·
Updated
2024-09-18
·
CVE-2024-27113
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SO Planning tool versions prior to 1.52.02
Description
An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this issue to gain access to the underlying database by exporting it as a CSV file.
Recommendations
For versions prior to 1.52.02, update to version 1.52.02 to resolve the issue. As a temporary workaround, consider disabling the public view setting until the update is applied. Restrict access to the database export functionality to minimize the risk of exploitation.
Fix
IDOR
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
So Planning Tool