SQL Injection Vulnerability in SOPlanning by Ingenius
CVE-2024-9573
6.3MEDIUM
What is CVE-2024-9573?
An SQL injection vulnerability exists in SOPlanning versions prior to 1.45, which can be exploited through the 'by' parameter in the endpoint /soplanning/www/groupe_list.php. This flaw allows an attacker to send specially crafted queries, potentially enabling unauthorized access to sensitive information stored on the server. Organizations using affected versions of SOPlanning should take immediate action to patch this security risk.
Affected Version(s)
SOPlanning 0 < 1.45
