vendor:
SOPlanning
by:
J3rryBl4nks
N/A
CVSS
N/A
Cross-Site Request Forgery
CWE
Product Name: SOPlanning
Affected Version From: 1.45
Affected Version To: 1.45
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10, Kali Rolling
2020
SOPlanning 1.45 – Cross-Site Request Forgery (Add User)
The SoPlanning 1.45 application is vulnerable to CSRF that allows for arbitrary user creation and for changing passwords (Specifically the admin password)