PT-2026-45357 · Soplanning · Soplanning
Łukasz Jaworski
·
Published
2026-06-01
·
Updated
2026-06-01
·
CVE-2026-40544
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N |
SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload backup endpoint. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a malicious user.csv file with embedded JavaScript. The injected code is executed in the victim’s browser when a user clicks the Edit button for the malicious backup.
This issue affects SOPlanning version 1.55 and below.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Soplanning