An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database by exporting it as a CSV file. The vulnerability has been remediated in version 1.52.02.
When the public view option is enabled in SO Planning, the application does not verify the user's identity or permissions before providing access to database resources. An attacker can directly reference a database object (IDOR) without any authentication. By exploiting this flaw, it is possible to export the entire database as a CSV file, leading to the disclosure of stored data.
An attacker can gain unauthorized access to the complete contents of the SO Planning application database and export it as a CSV file. This may result in a leak of sensitive data, including user personal data, schedules, and other information stored in the system.
SO Planning should be updated to version 1.52.02 or later, in which the vulnerability has been fixed. As a temporary workaround, consider disabling the public view option until the update is applied.
SO Planning (Soplanning) in versions prior to 1.52.02, when the public view setting is enabled.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:C/RE:M/U:RedSoplanning
APPSoplanning< 1.52.02
Related vulnerabilities
SOPlanning 1.53.00 — ominięcie ograniczeń przesyłania plików prowadzące do RCE
SQL Injection w SOPlanning — dostęp do całej bazy danych
Nieuwierzytelniony RCE w SO Planning — nieograniczony upload plików
SQL Injection w SO Planning — dostęp do bazy bez uwierzytelnienia
SOPlanning — hardcoded klucz admina umożliwia nieautoryzowany dostęp