PT-2024-39694 · Unknown · Soplanning

Rafael Pedrero

·

Published

2024-10-07

·

Updated

2024-10-08

·

CVE-2024-9573

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SOPlanning versions prior to 1.45
Description The issue allows a remote user to send a specially crafted query and extract all the information stored on the server through the /soplanning/www/groupe list.php endpoint, specifically in the by parameter.
Recommendations For SOPlanning versions prior to 1.45, consider disabling access to the /soplanning/www/groupe list.php endpoint until a patch is available. Restrict the use of the by parameter in this endpoint to minimize the risk of exploitation. Update to a version 1.45 or later to resolve the issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-9573

Affected Products

Soplanning