5.3
CVSSv3

CVE-2020-25867

Published: 07/10/2020 Updated: 15/10/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

SoPlanning prior to 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentication.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

soplanning soplanning

Github Repositories

CVE-2020-25867 : SoPlanning Sharing Key Bypass Information Vulnerable Version : 14601 Fixed Version : 147 and above CVE : CVE-2020-25867 Timeline 26/06/2020 : This vulnerability report was sent to the vendor 21/07/2020 : The vulnerability is fixed Risks The sharing key system is vulnerable to PHP Type Juggling attack, which allows an attacker to access the content of the