PT-2026-45359 · Unknown · Soplanning
Łukasz Jaworski
·
Published
2026-06-01
·
Updated
2026-06-01
·
CVE-2026-40546
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SOPlanning versions prior to 1.56
Description
SQL Injection allows an attacker with low privileges to inject arbitrary SQL commands, which could lead to full control over the database.
Recommendations
Update to a version newer than 1.55.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Soplanning