PT-2025-11625 · Unknown · Soplanning
Published
2025-03-18
·
Updated
2025-03-18
·
CVE-2024-57169
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SOPlanning version 1.53.00
Description
A file upload bypass issue exists, specifically in the "/process/upload.php" API endpoint, allowing remote attackers to bypass upload restrictions and potentially achieve remote code execution by uploading malicious files.
Recommendations
For SOPlanning version 1.53.00, consider disabling the file upload functionality in the "/process/upload.php" endpoint until a patch is available to prevent exploitation. Restrict access to the upload feature to minimize the risk of malicious file uploads.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Soplanning