Vulnerabilities (CVE)

Filtered by vendor Soplanning Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25867 1 Soplanning 1 Soplanning 2020-10-15 4.3 MEDIUM 5.3 MEDIUM
SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentication.
CVE-2020-15597 1 Soplanning 1 Soplanning 2020-08-13 3.5 LOW 5.4 MEDIUM
SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment field.
CVE-2020-9338 1 Soplanning 1 Soplanning 2020-02-24 3.5 LOW 5.4 MEDIUM
SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.
CVE-2020-9339 1 Soplanning 1 Soplanning 2020-02-24 3.5 LOW 5.4 MEDIUM
SOPlanning 1.45 allows XSS via the Name or Comment to status.php.
CVE-2020-9266 1 Soplanning 1 Soplanning 2020-02-19 4.3 MEDIUM 6.5 MEDIUM
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
CVE-2020-9267 1 Soplanning 1 Soplanning 2020-02-19 4.3 MEDIUM 6.5 MEDIUM
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
CVE-2014-8674 1 Soplanning 1 Soplanning 2020-01-10 3.5 LOW 5.4 MEDIUM
Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET parameter to export.php, which allows malicious users to execute arbitrary code.
CVE-2014-8677 1 Soplanning 1 Soplanning 2017-09-06 3.5 LOW 5.3 MEDIUM
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2 is being used, the configuration database is down, and smarty/templates_c is not writable to execute arbitrary php code via a crafted database name.
CVE-2014-8676 1 Soplanning 1 Soplanning 2017-09-05 5.0 MEDIUM 5.3 MEDIUM
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.