Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'LOGOUT_REDIRECT' parameter in '/soplanning/www/process/options.php'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.

Project Subscriptions

Vendors Products
Soplanning Subscribe
Soplanning Subscribe
Advisories

No advisories yet.

Fixes

Solution

The manufacturer says that is working on a version to fix the vulnerability.


Workaround

No workaround given by the vendor.

History

Fri, 21 Nov 2025 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:soplanning:soplanning:1.53.02:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Wed, 12 Nov 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Soplanning
Soplanning soplanning
Vendors & Products Soplanning
Soplanning soplanning

Mon, 10 Nov 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Nov 2025 10:00:00 +0000

Type Values Removed Values Added
Description Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored XSS due to a lack of proper validation of user input by sending a POST request using the 'LOGOUT_REDIRECT' parameter in '/soplanning/www/process/options.php'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.
Title Cross-Site Scripting (XSS) in SOPlanning
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-11-10T12:50:32.728Z

Reserved: 2025-04-16T09:08:41.550Z

Link: CVE-2025-41001

cve-icon Vulnrichment

Updated: 2025-11-10T12:50:28.774Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-10T10:15:35.550

Modified: 2025-11-21T21:17:53.797

Link: CVE-2025-41001

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-12T12:50:19Z

Weaknesses