3.5
CVSSv2

CVE-2014-8674

Published: 06/01/2020 Updated: 10/01/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) prior to 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET parameter to export.php, which allows malicious users to execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

soplanning soplanning

Exploits

SOPlanning - Simple Online Planning Tool multiple vulnerabilities CVEs: CVE-2014-8673, CVE-2014-8674, CVE-2014-8675, CVE-2014-8676, CVE-2014-8677 Vendor: wwwsoplanningorg/ Product: SOPlanning - Simple Online Planning Version affected: 132 and prior Product description: SO Planning is an open source online planning tool completely free, ...
Simple Online Planning Tool version 132 suffers from code execution, cross site scripting, remote SQL injection, information disclosure, and path traversal vulnerabilities ...