Cross-Site Request Forgery in SOPlanning by SOPlanning Team
CVE-2026-40549
5.1MEDIUM
What is CVE-2026-40549?
SOPlanning is susceptible to Cross-Site Request Forgery (CSRF) attacks through its groupe_save endpoints used for creating, modifying, and deleting records. This vulnerability allows malicious parties to exploit the trust that a web application has in an authenticated user. When a user visits a malicious website, the attacker can execute unauthorized commands on behalf of the user, potentially compromising sensitive data and application integrity. This issue is present in SOPlanning versions 1.55 and earlier, necessitating immediate action to secure applications against potential exploitation.
Affected Version(s)
SOPlanning 0 <= 1.55
