VulnerabilityAnalyzed
CVE-2025-62293
SOPlanning is vulnerable to Broken Access Control in /status endpoint.
MEDIUM 5.3EPSS 0.17%
Does this matter?
Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.
Description
SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Status functionality an authenticated attacker is able to add, edit and delete any status. This issue was fixed in version 1.55.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.17% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- soplanning/soplanning
- Source
- cvd@cert.pl
References
- https://cert.pl/en/posts/2025/11/CVE-2025-62293Third Party Advisory
- https://www.soplanning.org/en/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.