SOPlanning is vulnerable to Stored XSS in /feries endpoint. Malicious attacker with access to public holidays feature is able to inject arbitrary HTML and JS into website, which will be rendered/executed when opening multiple pages. By default only administrators and users with special privileges are able to access this endpoint.
This issue was fixed in version 1.55.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SOPlanning is vulnerable to Stored XSS in /feries endpoint. Malicious attacker with access to public holidays feature is able to inject arbitrary HTML and JS into website, which will be rendered/executed when opening multiple pages. By default only administrators and users with special privileges are able to access this endpoint. This issue was fixed in version 1.55. | |
| Title | Stored XSS in SOPlanning | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2025-11-20T15:44:17.319Z
Updated: 2025-11-21T16:24:55.256Z
Reserved: 2025-10-21T08:38:21.282Z
Link: CVE-2025-62731
Updated: 2025-11-21T16:24:51.828Z
Status : Awaiting Analysis
Published: 2025-11-20T16:16:00.363
Modified: 2025-11-21T15:13:13.800
Link: CVE-2025-62731
No data.