Cross-Site Scripting Vulnerabilities in Simple Online Planning by SOPlanning
CVE-2014-8674

5.4MEDIUM

Key Information:

Vendor

Soplanning

Vendor
CVE Published:
6 January 2020

What is CVE-2014-8674?

Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Simple Online Planning prior to version 1.33. These vulnerabilities arise from improper handling of user inputs through parameters like 'document.cookie' in 'nb_mois' and 'mb_ligness' as well as the 'debug' GET parameter in the 'export.php' file. Exploitation of these weaknesses can allow attackers to execute arbitrary code, potentially compromising the integrity and confidentiality of the application and its users. It is crucial for users and administrators to update to the latest version to mitigate these security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.