CVE-2024-27114

CRITICAL

SO Planning < 1.52.02 Public View Upload - Remote Code Execution

Title source: manual
STIX 2.1

Description

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is removed, leading to execution of code on the underlying system. The vulnerability has been remediated in version 1.52.02.

References (1)

Core 1
Core References
Broken Link third-party-advisory
https://csirt.divd.nl/CVE-2024-27114

Scores

CVSS v3 9.8
EPSS 0.0052
EPSS Percentile 40.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-367
Status published
Products (1)
soplanning/soplanning < 1.52.02
Published Sep 11, 2024
Tracked Since Feb 18, 2026