This issue was fixed in version 1.56.01.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 09 Jul 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Soplanning
Soplanning soplanning |
|
| Vendors & Products |
Soplanning
Soplanning soplanning |
|
| Metrics |
ssvc
|
Thu, 09 Jul 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands into the audit configuration form which is then saved. The execution is triggered when the audit functionality is accessed (by the attacker or another user). This issue was fixed in version 1.56.01. | |
| Title | SQL Injection in SOPlanning Audit Retention Configuration | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-07-09T12:09:06.573Z
Reserved: 2026-06-05T13:27:10.270Z
Link: CVE-2026-50644
Updated: 2026-07-09T12:09:03.218Z
Status : Deferred
Published: 2026-07-09T11:16:39.887
Modified: 2026-07-09T19:49:55.763
Link: CVE-2026-50644
No data.
OpenCVE Enrichment
Updated: 2026-08-01T14:45:06Z