This issue was fixed in version 1.55.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 20 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This allow a malicious authenticated attacker with this role to escalate to admin privileges. This issue affects both Bulk Update functionality and regular edition of user's right and privileges. This issue was fixed in version 1.55. | |
| Title | Privilege Escalation via Incorrect Authorization in SOPlanning | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-11-20T21:24:56.253Z
Reserved: 2025-10-21T08:11:07.742Z
Link: CVE-2025-62730
Updated: 2025-11-20T21:24:52.994Z
Status : Awaiting Analysis
Published: 2025-11-20T16:16:00.180
Modified: 2025-11-21T15:13:13.800
Link: CVE-2025-62730
No data.
OpenCVE Enrichment
No data.