CRITICAL🇵🇱 Wersja polska

CVE-2024-27112

CVSS 9.3v4.0pub. 2024-09-11upd. 2024-09-18

A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database. The vulnerability has been remediated in version 1.52.02.

🤖 AI Analysis
How it works

The vulnerability exists in the public view functionality of the SO Planning application. When this option is enabled, an unauthenticated user can submit malicious queries containing embedded SQL code. The application does not properly filter input data, so the injected SQL code is executed directly by the database engine. Classified as CWE-89 (SQL Injection), the vulnerability requires no user interaction or special privileges.

Impact

An attacker can gain unauthorized access to the entire contents of the application's database, including potentially sensitive data, user data, and system configuration. Depending on the permissions of the database account, it is also possible to modify or delete data.

Mitigation & patch

SO Planning should be updated to version 1.52.02 or newer, in which the vulnerability has been fixed. Until an update is performed, it is recommended to disable the public view option in the application configuration.

Who is affected

SO Planning (Soplanning) in versions earlier than 1.52.02, when the public view (public view) option is enabled.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:M/U:Red
  • Soplanning

    APP
    Soplanning
    < 1.52.02
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2024-57169CRITICAL9.8PL ✓same product

SOPlanning 1.53.00 — ominięcie ograniczeń przesyłania plików prowadzące do RCE

CVE-2024-9574CRITICAL9.8PL ✓same product

SQL Injection w SOPlanning — dostęp do całej bazy danych

CVE-2024-27115CRITICAL10.0PL ✓same product

Nieuwierzytelniony RCE w SO Planning — nieograniczony upload plików

CVE-2024-27113CRITICAL9.3PL ✓same product

IDOR w SO Planning umożliwia nieuwierzytelniony eksport bazy danych

CVE-2020-13963CRITICAL9.8PL ✓same product

SOPlanning — hardcoded klucz admina umożliwia nieautoryzowany dostęp