PT-2025-47599 · Unknown · Soplanning

Published

2025-11-20

·

Updated

2025-11-24

·

CVE-2025-62730

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SOPlanning versions prior to 1.55
Description SOPlanning has a flaw that allows privilege escalation through the user management tab. Users assigned the user manage team role can modify user permissions, including granting administrative privileges to themselves or other users. This allows a malicious, authenticated attacker with the user manage team role to escalate their privileges to administrator level. The issue affects both the Bulk Update functionality and the standard user rights and privileges editing process.
Recommendations Update to version 1.55 or later.

Fix

LPE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-62730

Affected Products

Soplanning