This issue was fixed in version 1.55.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Nov 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Soplanning
Soplanning soplanning |
|
| Vendors & Products |
Soplanning
Soplanning soplanning |
Thu, 20 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SOPlanning is vulnerable to Stored XSS in /projets endpoint. Malicious attacker with medium privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when opening edited page. This issue was fixed in version 1.55. | |
| Title | Stored XSS in SOPlanning | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-11-20T21:24:11.180Z
Reserved: 2025-10-10T06:53:21.425Z
Link: CVE-2025-62297
Updated: 2025-11-20T21:24:08.548Z
Status : Analyzed
Published: 2025-11-20T16:15:59.753
Modified: 2025-11-24T13:52:15.827
Link: CVE-2025-62297
No data.
OpenCVE Enrichment
Updated: 2025-11-24T09:10:47Z