5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Description
SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Status functionality an authenticated attacker is able to add, edit and delete any status.
This issue was fixed in version 1.55.
This issue was fixed in version 1.55.
Basic Information
ID
CVE-2025-62293
Source
CERT-PL
Published
Nov 20, 2025 at 15:43
Modified
Nov 20, 2025 at 19:17
Affected Product
Vendor
SOPlanning
Product
SOPlanning
Affected Versions
SOPlanning SOPlanning 0