Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Privilege Escalation via Incorrect Authorization in SOPlanning
Vulnerability Description
SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This allow a malicious authenticated attacker with this role to escalate to admin privileges. This issue affects both Bulk Update functionality and regular edition of user's right and privileges. This issue was fixed in version 1.55.
CVSS Information
N/A
Vulnerability Type
授权机制不正确
Vulnerability Title
SOPlanning 安全漏洞
Vulnerability Description
SOPlanning是SOPlanning公司的一套在线项目管理软件。 SOPlanning 1.55之前版本存在安全漏洞,该漏洞源于用户管理选项卡中权限分配不当,可能导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A