CVE-2014-8674
06.01.2020, 22:15
Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET parameter to export.php, which allows malicious users to execute arbitrary code.
Vendor | Product | Version |
---|---|---|
soplanning | soplanning | 𝑥 < 1.33 |
𝑥
= Vulnerable software versions
References