Stored XSS Vulnerability in SOPlanning by SOPlanning Team
CVE-2025-62296
5.1MEDIUM
What is CVE-2025-62296?
SOPlanning is prone to a stored Cross-Site Scripting (XSS) vulnerability located at the /taches endpoint. An attacker with medium privileges can exploit this flaw to inject arbitrary HTML and JavaScript code, which would then be executed within the editor environment. This could allow the attacker to manipulate session information or perform malicious actions on behalf of other users. This vulnerability was addressed in version 1.55 of SOPlanning. Users are recommended to upgrade to the latest version to mitigate potential risks.
Affected Version(s)
SOPlanning 0 < 1.55
