CVE-2020-13963

CRITICAL

SOPlanning < 1.47 - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation code, and there is no key for publicsp (which is a guest account).

References (3)

Core 3
Core References
Vendor Advisory x_refsource_misc
https://forum.soplanning.org/viewforum.php?f=8
Third Party Advisory x_refsource_misc
https://labs.integrity.pt/advisories/cve-2020-13963/
Technical Description x_refsource_misc
https://cwe.mitre.org/data/definitions/321.html

Scores

CVSS v3 9.8
EPSS 0.0181
EPSS Percentile 75.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (1)
soplanning/soplanning 1.45 - 1.47
Published Mar 21, 2021
Tracked Since Feb 18, 2026