SOPlanning是SOPlanning公司的一套在线项目管理软件。 SOPlanning 1.55及之前版本存在安全漏洞,该漏洞源于未对备份功能实施授权,可能导致未经身份验证的攻击者直接查询备份相关端点并检索包含用户数据库、用户名和密码哈希以及敏感信息的config.csv文件的备份存档。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SOPlanning | SOPlanning | ≤ 1.55 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SOPlanning | SOPlanning | 0 ~ 1.55 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40545 | Reflected XSS in SOPlanning | |
| CVE-2026-40546 | Multiple SQL Injections in SOPlanning | |
| CVE-2026-40548 | Unrestricted Upload of File with Dangerous Type in SOPlanning | |
| CVE-2026-40549 | Cross-Site Request Forgery in SOPlanning | |
| CVE-2026-40544 | Stored XSS in SOPlanning | |
| CVE-2026-40547 | Path Traversal in SOPlanning |
No comments yet