vendor:
SOPlanning
by:
J3rryBl4nks
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: SOPlanning
Affected Version From: 1.45
Affected Version To: 1.45
Patch Exists: NO
Related CWE: N/A
CPE: a:soplanning:soplanning:1.45
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10/Kali Rolling
2020
SOPlanning 1.45 – ‘by’ SQL Injection
The SOPlanning 1.45 application is vulnerable to SQL Injection which can be leveraged into getting the information for the users table.
Mitigation:
Input validation and sanitization should be done on user input to prevent SQL Injection.