First published: Wed Oct 07 2020(Updated: )
SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentication.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Soplanning Soplanning | <1.47 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-25867.
The severity of CVE-2020-25867 is medium (CVSS score 5.3).
CVE-2020-25867 affects SoPlanning versions up to and including 1.47.
CVE-2020-25867 allows unauthorized access to publicly shared plannings in SoPlanning.
Yes, the fix for CVE-2020-25867 is to upgrade SoPlanning to version 1.48 or higher.