First published: Tue Feb 18 2020(Updated: )
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Soplanning Soplanning | =1.45 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-9266.
The severity of CVE-2020-9266 is medium with a CVSS score of 6.5.
The vulnerability in SOPlanning 1.45 manifests as a CSRF attack that allows for arbitrary changing of the admin password via process/xajax_server.php.
SOPlanning 1.45 is the version affected by this vulnerability.
At the moment, there is no known fix available for CVE-2020-9266. It is recommended to update to a newer version of the software if one becomes available.