SOPlanning
cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*
- 1.52.00
A reflected cross-site scripting vulnerability has been identified in SOPlanning version 1.52.00. The issue arises in the 'groupe_id' parameter of 'process/groupe_save.php', allowing remote, unauthenticated attackers to inject malicious scripts. This vulnerability could be exploited to hijack the session or credentials of an authenticated user, including an admin, potentially leading to a complete takeover of the platform.
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
To reproduce this vulnerability, send a request to 'process/groupe_save.php' with the 'groupe_id' parameter set to a script payload, such as a JavaScript alert. The injected script will be executed, demonstrating the cross-site scripting vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.