CVE-2024-9571
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-9571 is a Cross-Site Scripting (XSS) vulnerability affecting SOPlanning versions below 1.45. The issue stems from a lack of sufficient input validation in the /soplanning/www/process/xajax_server.php file, which exposes multiple parameters to this concern. Maliciously crafted queries can be sent to authenticated users, leading to a partial takeover of their browser sessions by an attacker. This could potentially result in data theft or further exploitation. Users are strongly advised to update to the latest version of SOPlanning to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- SOPlanning