Vulnerabilities > Soplanning > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-09-11 CVE-2024-27112 SQL Injection vulnerability in Soplanning
A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled.
network
low complexity
soplanning CWE-89
critical
9.8
2024-09-11 CVE-2024-27113 Authorization Bypass Through User-Controlled Key vulnerability in Soplanning
An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled.
network
low complexity
soplanning CWE-639
critical
9.8
2024-09-11 CVE-2024-27114 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Soplanning
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool.
network
low complexity
soplanning CWE-367
critical
9.8
2024-09-11 CVE-2024-27115 Unrestricted Upload of File with Dangerous Type vulnerability in Soplanning
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool.
network
low complexity
soplanning CWE-434
critical
9.8
2021-03-21 CVE-2020-13963 Use of Hard-coded Credentials vulnerability in Soplanning 1.45/1.46.01
SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public.
network
low complexity
soplanning CWE-798
critical
9.8
2020-01-07 CVE-2014-8673 SQL Injection vulnerability in Soplanning
Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33.
network
low complexity
soplanning CWE-89
critical
9.8