Executive brief
SOPlanning is an online project management and team scheduling tool. A security flaw in the backup system allows an authorized user to upload malicious files disguised within a backup archive. If combined with other known flaws, this could allow an attacker to take control of the server, potentially leading to data theft or service disruption.
Technical details
SOPlanning version 1.55 and below contains an unrestricted file upload vulnerability (CWE-434) in its backup functionality. The application does not validate the extensions of files contained within uploaded ZIP archives. An authenticated attacker with access to backup features can include a malicious file (such as a PHP script) alongside the expected 'user.csv' file. When combined with a path traversal vulnerability (CVE-2026-40547), the attacker can place the malicious file into a web-accessible directory and execute it, leading to remote code execution. Access to the backup functionality is required, which typically requires high privileges, though CVE-2026-40543 may allow unauthorized access to these endpoints.
Affected products
- SOPlanning SOPlanning 1.55 and below
Timeline
- 2026-06-01: disclosed: Vulnerability disclosed by CERT Polska
- 2026-06-01: advisory: CVE-2026-40548 published