First published: Thu Jan 09 2020(Updated: )
SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Soplanning Soplanning | <=1.45 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20179 is a vulnerability in SOPlanning 1.45 that allows for SQL injection via the user_list.php "by" parameter.
CVE-2019-20179 has a severity rating of 8.8 (high).
SOPlanning version 1.45 is affected by CVE-2019-20179.
The SQL injection can be exploited by manipulating the "by" parameter in the user_list.php file.
There is currently no known fix for CVE-2019-20179. It is recommended to update to a newer version of SOPlanning, if available, or apply any patches provided by the vendor.