Cross-Site Scripting in SOPlanning by 0xEmma
CVE-2020-9339
5.4MEDIUM
What is CVE-2020-9339?
SOPlanning version 1.45 is susceptible to Cross-Site Scripting (XSS) vulnerabilities due to improper handling of user inputs in the Name or Comment fields within the status.php page. Attackers can exploit this flaw to inject malicious scripts that are executed in the context of other users' browsers, potentially leading to session hijacking, data theft, or unauthorized actions.
