SOPlanning Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in SOPlanning version 1.52.00. The issue arises in the 'groupe_id' parameter of 'process/groupe_save.php', allowing remote, unauthenticated attackers to inject malicious scripts. This vulnerability could be exploited to hijack the session or credentials of an authenticated user, including an admin, potentially leading to a complete takeover of the platform.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Reproduction

To reproduce this vulnerability, send a request to 'process/groupe_save.php' with the 'groupe_id' parameter set to a script payload, such as a JavaScript alert. The injected script will be executed, demonstrating the cross-site scripting vulnerability.

Added: May 8, 2026, 6:29 AM
Updated: May 8, 2026, 6:29 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.6
remediation
0.0
relevance
7.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.