CVE-2020-25867
MEDIUMsoplanning < 1.47 - Unauthenticated Access via Security Key Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-25867. PoCs published by thomasfady.
AI-analyzed exploit summary The repository describes a PHP Type Juggling vulnerability in SoPlanning 1.46.01, where the sharing key validation can be bypassed by passing an array instead of a string, allowing unauthorized access to the calendar. The exploit leverages the loose comparison behavior of the strcmp function in PHP.
Description
SoPlanning before 1.47 doesn't correctly check the security key used to publicly share plannings. It allows a bypass to get access without authentication.
Exploits (1)
The repository describes a PHP Type Juggling vulnerability in SoPlanning 1.46.01, where the sharing key validation can be bypassed by passing an array instead of a string, allowing unauthorized access to the calendar. The exploit leverages the loose comparison behavior of the strcmp function in PHP.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N