Record summary

CVE-2024-27115 has a selected CVSS score of 10.0 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any requirements. This leads to the possibility of execution of code on the underlying system when the file is triggered. The vulnerability has been remediated in version 1.52.02.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 11, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected, unknown

CVE Listbefore 1.52.01affected
Before 1.52.01affected

Proofs of concept

1

Repository PoCs

GitHubtheexploiters/CVE-2024-27115-ExploitRepository PoCby theexploitersStars: 3Not analyzed2 files

4.4 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHSOPlanning - Remote Code ExecutionCVSS 10

Detects a remote code execution vulnerability in SOPlanning version 1.52.01 through authenticated PHP file upload.

Impact

Authenticated attackers can upload and execute arbitrary PHP files through the SOPlanning upload functionality, achieving remote code execution.

Remediation

Update SOPlanning to a version newer than 1.52.01.

WeaknessesCWE-434
Authorssoonghee2@ajou.ac.kr
Template tagscvecve2024soplanningrceauthenticatedfile-uploadintrusivevuln
CVSS vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:I/V:C/RE:M/U:Red
CPE: cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2