Impact
SOPlanning is vulnerable to SQL injection (CWE‑89) in the audit retention configuration. An attacker holding parameters_all rights can inject arbitrary SQL commands into a configuration form; the injected statements feature is accessed, either by the attacker or by other authenticated users. This flaw allows attackers to read, modify, or delete database contents, potentially compromising confidentiality, integrity, and availability of the system.
Affected Systems
The vulnerability affects SOPlanning product versions earlier than 1.56.01. Users must identify if their deployment runs a version prior to the fix and plan to upgrade accordingly.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity risk. The EPSS score of < 1% indicates a very low exploitation probability. The exploit is triggerable by accessing audit functionality, making it usable both by the injector and by other users. The vulnerability is not listed in CISA KEV but remains a significant security risk for affected installations.
OpenCVE Enrichment