Stored XSS Vulnerability in SOPlanning by SOPlanning.org
CVE-2025-62295
5.1MEDIUM
What is CVE-2025-62295?
SOPlanning contains a vulnerability that allows an attacker with medium-level privileges to inject arbitrary HTML and JavaScript code into the application via the /groupe_form endpoint. When this code is executed, it poses significant risks as it can be rendered when the editor is accessed, potentially compromising user data and web application integrity. This issue was addressed in version 1.55 of SOPlanning, and users are encouraged to update to this version to mitigate the risk.
Affected Version(s)
SOPlanning 0 < 1.55
