PT-2026-56774 · Unknown · Soplanning
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SOPlanning versions prior to 1.56.01
Description
SQL injection is possible within the audit retention configuration. An attacker with
parameters all rights can inject SQL commands into the audit configuration form. These commands are saved and subsequently executed when the audit functionality is accessed by any user.Recommendations
Update to version 1.56.01.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Soplanning