← Volver al buscador de CVEs

CVE-2026-40543

SOPlanning

Descripción

SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query backup-related endpoints and retrieve backup archives containing user databases with usernames and password hashes, as well as the config.csv file, which includes additional sensitive information. This issue affects SOPlanning version 1.55 and below.

CVSS 8.8EPSS 0.27299999999999996%Riesgo 0.9
Ver fuente
Publicación
2026-06-01 09:16:17
Versiones afectadas
<=1.55
Tipo
Package
Última modificación
2026-07-22 07:10:00
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X