First published: Sat Feb 22 2020(Updated: )
SOPlanning 1.45 allows XSS via the "Your SoPlanning url" field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Soplanning Soplanning | =1.45 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-9338.
The severity of CVE-2020-9338 is medium (5.4).
CVE-2020-9338 allows attackers to execute cross-site scripting (XSS) attacks via the "Your SoPlanning url" field in SOPlanning 1.45.
To fix CVE-2020-9338, update SOPlanning to a version that is not affected by this vulnerability.
Yes, you can find additional information about CVE-2020-9338 in the reference link: https://github.com/0xEmma/CVEs/blob/master/CVEs/2020-02-14-SoPlanning-Admin-XSS.md