CVE-2024-33724
SOPlanning 1.52.00 Cross Site Scripting
Record summary
CVE-2024-33724 has a selected CVSS score of 5.4 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.
Exploitation context
Proofs of concept
1Repository PoCs
GitLabfuzzlove-group/soplanning-1-52-exploitsRepository PoCby fuzzlove-groupStars: 0Not analyzed4 files
Nuclei templates
1ProjectDiscoveryMEDIUMSOPlanning 1.52.00 Cross Site Scripting
SOPlanning v1.52.00 is vulnerable to XSS via the 'groupe_id' parameters a remote unautheticated attacker can hijack the admin account or other users. The remote attacker can hijack a users session or credentials and perform a takeover of the entire platform.
Impact
Authenticated attackers can inject malicious scripts via the groupe_id parameter, potentially hijacking admin or user sessions.
Remediation
Update SOPlanning to a version that patches the XSS vulnerability.
Source: ProjectDiscovery