CVE-2024-57170

MEDIUM

SOPlanning 1.53.00 - Authenticated Path Traversal and Arbitrary File Deletion via fichier_to_delete Parameter

Title source: llm
STIX 2.1

Description

SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attackers to specify file paths containing directory traversal sequences (e.g., ../). This vulnerability enables attackers to delete arbitrary files outside the intended upload directory, potentially leading to denial of service or disruption of application functionality.

Scores

CVSS v3 6.5
EPSS 0.0084
EPSS Percentile 53.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
soplanning/soplanning 1.53.00
Published Mar 18, 2025
Tracked Since Feb 18, 2026