5
CVSSv2

CVE-2014-8675

Published: 31/08/2017 Updated: 06/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Soplanning 1.32 and previous versions generates static links for sharing ICAL calendars with embedded login information, which allows remote malicious users to obtain a calendar owner's password via a brute-force attack on the embedded password hash.

Vulnerable Product Search on Vulmon Subscribe to Product

soplanning soplanning

Exploits

SOPlanning - Simple Online Planning Tool multiple vulnerabilities CVEs: CVE-2014-8673, CVE-2014-8674, CVE-2014-8675, CVE-2014-8676, CVE-2014-8677 Vendor: wwwsoplanningorg/ Product: SOPlanning - Simple Online Planning Version affected: 132 and prior Product description: SO Planning is an open source online planning tool completely free, ...
Simple Online Planning Tool version 132 suffers from code execution, cross site scripting, remote SQL injection, information disclosure, and path traversal vulnerabilities ...