← Volver al buscador de CVEs

CVE-2026-40546

SOPlanning

Descripción

SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inject arbitrary SQL commands, potentially gaining full control over the database. This issue affects SOPlanning version 1.55 and below.

CVSS 8.7EPSS 0.211%Riesgo 0.89
Ver fuente
Publicación
2026-06-01 09:16:17
Versiones afectadas
<=1.55
Tipo
Core software
Última modificación
2026-07-22 07:10:00
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X