Vulnerability Description
SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Status functionality an authenticated attacker is able to add, edit and delete any status. This issue was fixed in version 1.55.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Soplanning | Soplanning | < 1.55.00 |
Related Weaknesses (CWE)
References
- https://cert.pl/en/posts/2025/11/CVE-2025-62293Third Party Advisory
- https://www.soplanning.org/en/Product
FAQ
What is CVE-2025-62293?
CVE-2025-62293 is a vulnerability with a CVSS score of 5.4 (MEDIUM). SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Status functionality an authenticated attacker is able to add, edit and delete any st...
How severe is CVE-2025-62293?
CVE-2025-62293 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-62293?
Check the references section above for vendor advisories and patch information. Affected products include: Soplanning Soplanning.