Skip to the content.

CVE-2024-27114

Remote Code Execution through File Upload in SOPlanning before 1.52.02

CVE CVE-2024-27114
Title Remote Code Execution through File Upload in SOPlanning before 1.52.02
Credits
Affected products
Product Affected Unaffected Unknown
Simple Online Planning SO Planning = before 1.52.01 ()
everything else
CVSS
Base score 8.9 - HIGH
Attack Vector NETWORK
Attack Complexity> LOW
Attack Requirements PRESENT
Privileges Required HIGH
Confidentiality Impact
Vulnerable system HIGH Subsequent systems HIGH
Integrity Impact
Vulnerable system HIGH Subsequent systems HIGH
Availability Impact
Vulnerable system HIGH Subsequent systems HIGH
Safety impact NEGLIGIBLE
Automatable YES
Recovery IRRECOVERABLE
Value Density CONCENTRATED
Vulnerability Response effort MODERATE
Provider Urgency RED
References https://csirt.divd.nl/CVE-2024-27114 ( third-party-advisory )
Problem type(s) CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
Impact(s) CAPEC-549 Local Execution of Code
Configuration(s) The public view setting must be enabled.
Date published
Last modified 11 Sep 2024 13:41 UTC

Description

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is removed, leading to execution of code on the underlying system. The vulnerability has been remediated in version 1.52.02. 

Workaround(s)

Disable the public view setting.


JSON version.