File Upload Vulnerability in SOPlanning Affects Server Security
CVE-2026-40548
6.4MEDIUM
What is CVE-2026-40548?
A file upload vulnerability in SOPlanning allows authenticated attackers to upload malicious files through the backup functionality without verifying the file extension. Specifically, an attacker can upload a crafted ZIP archive containing both a legitimate user.csv file and a harmful file, which is then extracted on the server. By exploiting this vulnerability in conjunction with another related issue that allows path traversal, the attacker can position a PHP script in a publicly accessible directory on the server, enabling remote code execution through a web browser.
Affected Version(s)
SOPlanning 0 <= 1.55
