This issue was fixed in version 1.55.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Nov 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Soplanning
Soplanning soplanning |
|
| Vendors & Products |
Soplanning
Soplanning soplanning |
Thu, 20 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SOPlanning is vulnerable to Stored XSS in /groupe_form endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening editor. This issue was fixed in version 1.55. | |
| Title | Stored XSS in SOPlanning | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-11-20T21:11:57.203Z
Reserved: 2025-10-10T06:53:21.425Z
Link: CVE-2025-62295
Updated: 2025-11-20T21:11:54.192Z
Status : Analyzed
Published: 2025-11-20T16:15:59.410
Modified: 2025-11-24T13:51:56.757
Link: CVE-2025-62295
No data.
OpenCVE Enrichment
Updated: 2025-11-24T09:10:31Z