Privilege Escalation in SOPlanning by Vendor SOPlanning
CVE-2025-62730

8.7HIGH

Key Information:

Vendor

Soplanning

Vendor
CVE Published:
20 November 2025

What is CVE-2025-62730?

SOPlanning suffers from a privilege escalation vulnerability within its user management tab. Authenticated users assigned the 'user_manage_team' role can improperly modify user permissions, allowing them to grant administrative access to themselves or other users. This security flaw, which can be exploited through both bulk updates and individual changes to user rights, poses a significant risk if left unaddressed. The issue has been resolved in version 1.55, highlighting the importance of maintaining updated software to mitigate security threats.

Affected Version(s)

SOPlanning 0 < 1.55

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62730 : Privilege Escalation in SOPlanning by Vendor SOPlanning