← Vulnerability feed

Vulnerability record · CVE-2025-62730 · published 20 November 2025

CVE-2025-62730: Soplanning incorrect authorization vulnerability

Soplanning · Soplanning

SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This allow a malicious authenticated attacker with this role to escalate to admin privileges. This issue affects both Bulk Update functionality and regular edition of user's right and privileges. This issue was fixed in version 1.55.

8.7 CVSS 4.0 High EPSS 0.29% · top 80.5% CWE-863 · Incorrect authorization
8.7CVSS 4.0 base score
0.29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This allow a malicious authenticated attacker with this role to escalate to admin privileges. This issue affects both Bulk Update functionality and regular edition of user's right and privileges. This issue was fixed in version 1.55.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-62730 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-27115Soplanning unrestricted file upload vulnerabilityA unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker ca…EPSS 4.6%9.8CVE-2024-57169Soplanning unrestricted file upload vulnerabilityA file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to b…EPSS 0.97%9.8CVE-2020-13963Soplanning hard-coded credentials vulnerabilitySOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The …EPSS 1.8%9.8CVE-2014-8673Soplanning sql injection vulnerabilityMultiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPP…EPSS 12%9.3CVE-2024-27112Soplanning sql injection vulnerabilityA unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use thi…EPSS 0.41%9.3CVE-2024-27113Soplanning information exposure vulnerabilityAn unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view se…EPSS 0.43%8.9CVE-2024-27114Soplanning toctou race condition vulnerabilityA unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, …EPSS 0.54%8.8CVE-2019-20179Soplanning sql injection vulnerabilitySOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2025-62730), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.