Vulnerabilities > Soplanning > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-08-11 | CVE-2020-15597 | Cross-site Scripting vulnerability in Soplanning SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment field. | 3.5 |
2020-02-22 | CVE-2020-9338 | Cross-site Scripting vulnerability in Soplanning 1.45 SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field. | 3.5 |
2020-02-22 | CVE-2020-9339 | Cross-site Scripting vulnerability in Soplanning 1.45 SOPlanning 1.45 allows XSS via the Name or Comment to status.php. | 3.5 |
2020-01-06 | CVE-2014-8674 | Cross-site Scripting vulnerability in Soplanning Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET parameter to export.php, which allows malicious users to execute arbitrary code. | 3.5 |
2017-08-31 | CVE-2014-8677 | Improper Access Control vulnerability in Soplanning The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2 is being used, the configuration database is down, and smarty/templates_c is not writable to execute arbitrary php code via a crafted database name. | 3.5 |