First published: Tue Feb 18 2020(Updated: )
SoPlanning 1.45 is vulnerable to SQL Injection in the OrderBy clause, as demonstrated by the projets.php?order=nom_createur&by= substring.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Soplanning Soplanning | =1.45 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9268 is a vulnerability in SoPlanning version 1.45 that allows SQL Injection in the OrderBy clause.
CVE-2020-9268 has a severity rating of 7.5 (high).
CVE-2020-9268 allows an attacker to perform SQL Injection in the OrderBy clause of SoPlanning version 1.45.
To fix CVE-2020-9268, you should update SoPlanning to a version that has fixed the SQL Injection vulnerability.
You can find more information about CVE-2020-9268 in the reference link provided: https://github.com/J3rryBl4nks/SOPlanning/blob/master/SQLInjectionProjects.md