Executive brief
SOPlanning, an online project management and team scheduling tool, is vulnerable to SQL injection. An attacker with low-level user access can send malicious commands to the database through various parts of the application. This could allow the attacker to view, modify, or delete sensitive business data, potentially gaining full control over the underlying database.
Technical details
SOPlanning version 1.55 and below contains multiple SQL injection vulnerabilities (CWE-89) across various endpoints and parameters. The root cause is improper neutralization of special elements used in SQL commands. An authenticated attacker with low-level privileges can exploit these flaws by sending crafted network requests to vulnerable endpoints. Successful exploitation allows for the execution of arbitrary SQL commands, which can lead to unauthorized data exfiltration, modification, or full database compromise. The vulnerability was coordinated and disclosed by CERT Polska.
Affected products
- SOPlanning SOPlanning All through 1.55
Timeline
- 2026-06-01: disclosed: Vulnerability disclosed by CERT Polska
- 2026-06-01: advisory: NVD published CVE-2026-40546