Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Remote Code Execution through File Upload in SOPlanning before 1.52.02
Vulnerability Description
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is removed, leading to execution of code on the underlying system. The vulnerability has been remediated in version 1.52.02.
CVSS Information
N/A
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Vulnerability Title
SOPlanning 安全漏洞
Vulnerability Description
SOPlanning是SOPlanning公司的一套在线项目管理软件。 SOPlanning存在安全漏洞。攻击者利用该漏洞可以在底层系统上执行代码。
CVSS Information
N/A
Vulnerability Type
N/A