A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database. The vulnerability has been remediated in version 1.52.02.
The vulnerability exists in the public view functionality of the SO Planning application. When this option is enabled, an unauthenticated user can submit malicious queries containing embedded SQL code. The application does not properly filter input data, so the injected SQL code is executed directly by the database engine. Classified as CWE-89 (SQL Injection), the vulnerability requires no user interaction or special privileges.
An attacker can gain unauthorized access to the entire contents of the application's database, including potentially sensitive data, user data, and system configuration. Depending on the permissions of the database account, it is also possible to modify or delete data.
SO Planning should be updated to version 1.52.02 or newer, in which the vulnerability has been fixed. Until an update is performed, it is recommended to disable the public view option in the application configuration.
SO Planning (Soplanning) in versions earlier than 1.52.02, when the public view (public view) option is enabled.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:M/U:RedSoplanning
APPSoplanning< 1.52.02
Related vulnerabilities
SOPlanning 1.53.00 — ominięcie ograniczeń przesyłania plików prowadzące do RCE
SQL Injection w SOPlanning — dostęp do całej bazy danych
Nieuwierzytelniony RCE w SO Planning — nieograniczony upload plików
IDOR w SO Planning umożliwia nieuwierzytelniony eksport bazy danych
SOPlanning — hardcoded klucz admina umożliwia nieautoryzowany dostęp