SQL Injection Vulnerability in SOPlanning by INTEK
CVE-2024-9574
9.8CRITICAL
What is CVE-2024-9574?
A SQL injection vulnerability exists in SOPlanning versions prior to 1.45, specifically through the /soplanning/www/user_groupes.php endpoint via the 'by' parameter. This flaw allows remote users to execute specially crafted SQL queries, potentially granting them unauthorized access to sensitive database information. Cybersecurity best practices recommend upgrading to the latest version to mitigate this risk.
Affected Version(s)
SOPlanning 0 < 1.45
