Record summary

CVE-2024-33724 has a selected CVSS score of 5.4 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2026 · Source: CVE List

Proofs of concept

1

Repository PoCs

GitLabfuzzlove-group/soplanning-1-52-exploitsRepository PoCby fuzzlove-groupStars: 0Not analyzed4 files

9.4 KiB · linked to 2 vulnerabilities

GitLab

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMSOPlanning 1.52.00 Cross Site Scripting

SOPlanning v1.52.00 is vulnerable to XSS via the 'groupe_id' parameters a remote unautheticated attacker can hijack the admin account or other users. The remote attacker can hijack a users session or credentials and perform a takeover of the entire platform.

Impact

Authenticated attackers can inject malicious scripts via the groupe_id parameter, potentially hijacking admin or user sessions.

Remediation

Update SOPlanning to a version that patches the XSS vulnerability.

Authorss4e-io
Template tagspacketstormcvecve2024authenticatedsoplanningxssvuln
Shodan: html:"soplanning"
Shodan: http.html:"soplanning"
FOFA: body="soplanning"

Source: ProjectDiscovery

References

3