SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attackers to specify file paths containing directory traversal sequences (e.g., ../). This vulnerability enables attackers to delete arbitrary files outside the intended upload directory, potentially leading to denial of service or disruption of application functionality.
References
Configurations
History
No history.
Information
Published : 2025-03-18 16:15
Updated : 2025-04-02 12:29
NVD link : CVE-2024-57170
Mitre link : CVE-2024-57170
CVE.ORG link : CVE-2024-57170
JSON object : View
Products Affected
soplanning
- soplanning
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
