PT-2025-47594 · Unknown · Soplanning
Łukasz Jaworski
·
Published
2025-11-20
·
Updated
2025-11-24
·
CVE-2025-62294
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SOPlanning versions prior to 1.55
Description
SOPlanning is susceptible to a weakness in its password recovery token generation process. The use of a weak mechanism for generating these tokens allows a malicious actor to potentially brute-force all possible values, leading to account takeover.
Recommendations
Update to version 1.55 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Soplanning