Junglewise Threat Intelligence

CVE-2026-40545: SOPlanning Reflected XSS in taches parameter

CVE-2026-40545 · Severity: info · CVSS 5.1 · Published 2026-06-01

Technologies: SOPlanning. Vendors: SOPlanning.

Executive brief

SOPlanning, an online project management and team scheduling tool, is vulnerable to a security flaw that could allow an attacker to execute malicious code in a user's browser. By tricking an authenticated user into clicking a specially crafted link, an attacker can steal session information or perform actions on behalf of that user. This could lead to unauthorized access to project schedules, resource management data, and other sensitive team information.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SOPlanning versions up to and including 1.55. The vulnerability is located in the 'taches' parameter, which fails to properly neutralize user-supplied input before rendering it in a web page. An unauthenticated remote attacker can exploit this by crafting a malicious URL and using social engineering to entice an authenticated victim to click it. Successful exploitation allows the execution of arbitrary JavaScript within the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. The issue was coordinated and disclosed by CERT Polska.

Affected products

  • SOPlanning SOPlanning All through 1.55

Timeline

  • 2026-06-01: disclosed: Vulnerability disclosed by CERT Polska
  • 2026-06-01: advisory: NVD record published

References

Related threats