Cross-Site Scripting Vulnerability in SOPlanning Software by SOPlanning
CVE-2024-9571

6.3MEDIUM

Key Information:

Vendor

Soplanning

Vendor
CVE Published:
7 October 2024

What is CVE-2024-9571?

A Cross-Site Scripting (XSS) vulnerability exists in SOPlanning, specifically in versions prior to 1.45, resulting from insufficient validation of user input. This flaw is triggered via the /soplanning/www/process/xajax_server.php endpoint, enabling remote attackers to craft specific queries. If successful, the attacker can inject malicious scripts into the browser sessions of authenticated users, potentially leading to unauthorized access and manipulation of user data. To safeguard against this vulnerability, users are urged to update to the latest version of SOPlanning and implement additional security practices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SOPlanning 0 < 1.45

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.