ZeroHour

CVE-2020-13963

CVSS 3.1
9.8 critical
EPSS
2%p77
Published
()
Modified
Description

SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation code, and there is no key for publicsp (which is a guest account).

Vendors
soplanning
Products
soplanning
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.