← Vulnerability feed

Vulnerability record · CVE-2024-27113 · published 11 September 2024

CVE-2024-27113: Soplanning information exposure vulnerability

Soplanning · Soplanning

An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database by exporting it as a CSV file. The vulnerability has been remediated in version 1.52.02.

9.3 CVSS 4.0 Critical EPSS 0.43% · top 65.8% CWE-200 · Information exposureCWE-639 · Insecure direct object reference
9.3CVSS 4.0 base score
0.43%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database by exporting it as a CSV file. The vulnerability has been remediated in version 1.52.02.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-27113 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-27115Soplanning unrestricted file upload vulnerabilityA unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker ca…EPSS 4.6%9.8CVE-2024-57169Soplanning unrestricted file upload vulnerabilityA file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to b…EPSS 0.97%9.8CVE-2020-13963Soplanning hard-coded credentials vulnerabilitySOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The …EPSS 1.8%9.8CVE-2014-8673Soplanning sql injection vulnerabilityMultiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPP…EPSS 12%9.3CVE-2024-27112Soplanning sql injection vulnerabilityA unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use thi…EPSS 0.41%8.9CVE-2024-27114Soplanning toctou race condition vulnerabilityA unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, …EPSS 0.54%8.8CVE-2019-20179Soplanning sql injection vulnerabilitySOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.EPSS 1.0%8.7CVE-2025-62730Soplanning incorrect authorization vulnerabilitySOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users.…EPSS 0.29%

Source: NIST National Vulnerability Database (record CVE-2024-27113), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.