First published: Sun Mar 21 2021(Updated: )
SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation code, and there is no key for publicsp (which is a guest account).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Soplanning Soplanning | >=1.45<1.47 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13963 is a vulnerability in SOPlanning before version 1.47 that allows incorrect access control due to certain secret key information and the related authentication algorithm being public.
The severity of CVE-2020-13963 is critical with a CVSS score of 9.8.
CVE-2020-13963 affects SOPlanning versions before 1.47 by exposing certain secret key information and not having a key for the guest account.
To fix CVE-2020-13963 in SOPlanning, update to version 1.47 or later.
More information about CVE-2020-13963 can be found in the following references: [1] [2] [3]