SOPlanning
cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*
- < 1.55
A broken access control vulnerability has been identified in SOPlanning, specifically in the Project Status functionality of the '/status' endpoint. This vulnerability allows authenticated attackers to add, edit, and delete any status, due to the absence of proper permission checks. The issue affects all versions prior to 1.55.
Exploitation of this vulnerability allows for unauthorized modification of project status, including the addition, editing, and deletion of status entries.
Users can upgrade to SOPlanning version 1.55 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.