Vulnerabilities (CVE)

Filtered by vendor Soplanning Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13963 1 Soplanning 1 Soplanning 2022-07-10 7.5 HIGH 9.8 CRITICAL
SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation code, and there is no key for publicsp (which is a guest account).
CVE-2014-8673 1 Soplanning 1 Soplanning 2020-01-08 7.5 HIGH 9.8 CRITICAL
Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33.