SOPlanning v1.46.01 XSS / Session Hijack
- by Vince
-
in Blog
-
Hits: 5559
Disclosure Date: 07/06/2020
CVE-2020-15597
SOPlanning v1.46.01 and possibly before are affected by a persistent cross site scripting vulnerability that can be leveraged for session hijacking. An attacker can exploit the XSS vulnerability, retrieve the session cookie from the administrator login, and take over the administrator account.