SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attackers to specify file paths containing directory traversal sequences (e.g., ../). This vulnerability enables attackers to delete arbitrary files outside the intended upload directory, potentially leading to denial of service or disruption of application functionality.
References
Configurations
History
02 Apr 2025, 12:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://themcsam.github.io/posts/so-planing-vulnerabilities/#arbitrary-file-deletion - Exploit | |
First Time |
Soplanning
Soplanning soplanning |
|
CPE | cpe:2.3:a:soplanning:soplanning:1.53.00:*:*:*:*:*:*:* |
25 Mar 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
Summary |
|
|
References | () https://themcsam.github.io/posts/so-planing-vulnerabilities/#arbitrary-file-deletion - | |
CWE | CWE-22 |
18 Mar 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-18 16:15
Updated : 2025-04-02 12:29
NVD link : CVE-2024-57170
Mitre link : CVE-2024-57170
CVE.ORG link : CVE-2024-57170
JSON object : View
Products Affected
soplanning
- soplanning
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')