Cross-Site Scripting Vulnerability in SOPlanning Software by SOPlanning
CVE-2024-9571
6.3MEDIUM
What is CVE-2024-9571?
A Cross-Site Scripting (XSS) vulnerability exists in SOPlanning, specifically in versions prior to 1.45, resulting from insufficient validation of user input. This flaw is triggered via the /soplanning/www/process/xajax_server.php endpoint, enabling remote attackers to craft specific queries. If successful, the attacker can inject malicious scripts into the browser sessions of authenticated users, potentially leading to unauthorized access and manipulation of user data. To safeguard against this vulnerability, users are urged to update to the latest version of SOPlanning and implement additional security practices.
Affected Version(s)
SOPlanning 0 < 1.45
