This issue was fixed in version 1.55.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Nov 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Soplanning
Soplanning soplanning |
|
| Vendors & Products |
Soplanning
Soplanning soplanning |
Thu, 20 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SOPlanning is vulnerable to Stored XSS in /taches endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening editor. This issue was fixed in version 1.55. | |
| Title | Stored XSS in SOPlanning | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-11-20T21:21:16.375Z
Reserved: 2025-10-10T06:53:21.425Z
Link: CVE-2025-62296
Updated: 2025-11-20T21:21:13.237Z
Status : Analyzed
Published: 2025-11-20T16:15:59.583
Modified: 2025-11-24T13:52:06.957
Link: CVE-2025-62296
No data.
OpenCVE Enrichment
Updated: 2025-11-24T09:10:31Z