CVE-2026-40549 PUBLISHED

Cross-Site Request Forgery in SOPlanning

Assigner: CERT-PL
Reserved: 14.04.2026 Published: 01.06.2026 Updated: 01.06.2026

SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An attacker can craft a malicious website that, when visited by an authenticated user, automatically sends a forged GET or POST request to the application.

This issue affects SOPlanning version 1.55 and below.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor SOPlanning
Product SOPlanning
Versions Default: unaffected
  • affected from 0 to 1.55 (incl.)

Credits

  • Łukasz Jaworski finder

References

Problem Types

  • CWE-352 Cross-Site Request Forgery (CSRF) CWE

Impacts

  • CAPEC-62 Cross Site Request Forgery