CVE-2025-62297 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

SOPlanning is vulnerable to Stored XSS in /projets endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will…
Medium CVSS: 5.1

CVE-2025-62297

SOPlanning is vulnerable to Stored XSS in /projets endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening edited page.

This issue was fixed in version 1.55.
Vendor
Soplanning
Product
Soplanning
CWE
CWE-79
Yayın Tarihi
2025-11-20 16:15:59
Güncelleme
2025-11-24 13:52:15
Source Identifier
cvd@cert.pl
KEV Date Added
-

Kategoriler

Referanslar