Vulnerabilities > Soplanning > Low

DATE CVE VULNERABILITY TITLE RISK
2020-08-11 CVE-2020-15597 Cross-site Scripting vulnerability in Soplanning
SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment field.
network
soplanning CWE-79
3.5
2020-02-22 CVE-2020-9338 Cross-site Scripting vulnerability in Soplanning 1.45
SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.
network
soplanning CWE-79
3.5
2020-02-22 CVE-2020-9339 Cross-site Scripting vulnerability in Soplanning 1.45
SOPlanning 1.45 allows XSS via the Name or Comment to status.php.
network
soplanning CWE-79
3.5
2020-01-06 CVE-2014-8674 Cross-site Scripting vulnerability in Soplanning
Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET parameter to export.php, which allows malicious users to execute arbitrary code.
network
soplanning CWE-79
3.5
2017-08-31 CVE-2014-8677 Improper Access Control vulnerability in Soplanning
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2 is being used, the configuration database is down, and smarty/templates_c is not writable to execute arbitrary php code via a crafted database name.
3.5