CVE-2024-27114
A unauthenticated Remote Code Execution (RCE) vulnerability is found in

Publication date: 2024-09-11

Last updated on: 2024-09-19

Assigner: [email protected]

Description
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is removed, leading to execution of code on the underlying system. The vulnerability has been remediated in version 1.52.02.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Affected Vendors & Products
Vendor Product Version
soplanning soplanning to 1.52.02 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
Attack-Flow Graph
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart
Meta Information
CVE Publication Date:
2024-09-11
CVE Last Modified Date:
2024-09-19
Report Generation Date:
2025-11-06
EPSS Last Evaluated Date:
2025-08-20
NVD Report Link: