File Upload Vulnerability in SOPlanning Affects Server Security
CVE-2026-40548

6.4MEDIUM

Key Information:

Vendor

Soplanning

Vendor
CVE Published:
1 June 2026

What is CVE-2026-40548?

A file upload vulnerability in SOPlanning allows authenticated attackers to upload malicious files through the backup functionality without verifying the file extension. Specifically, an attacker can upload a crafted ZIP archive containing both a legitimate user.csv file and a harmful file, which is then extracted on the server. By exploiting this vulnerability in conjunction with another related issue that allows path traversal, the attacker can position a PHP script in a publicly accessible directory on the server, enabling remote code execution through a web browser.

Affected Version(s)

SOPlanning 0 <= 1.55

References

CVSS V4

Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Łukasz Jaworski
.