PT-2024-39695 · Unknown · Soplanning
Rafael Pedrero
·
Published
2024-10-07
·
Updated
2024-10-09
·
CVE-2024-9574
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SOPlanning versions prior to 1.45
Description
A SQL injection issue exists in SOPlanning, which could allow a remote user to submit a specially crafted query via the "by" parameter in the /soplanning/www/user groupes.php API endpoint, allowing an attacker to retrieve all the information stored in the database.
Recommendations
For SOPlanning versions prior to 1.45, upgrade to a version 1.45 or later to resolve the issue. As a temporary workaround, consider restricting access to the /soplanning/www/user groupes.php API endpoint and the
by parameter to minimize the risk of exploitation.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Soplanning