CVE-2026-40549
Vulnerability Description
SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An attacker can craft a malicious website that, when visited by an authenticated user, automatically sends a forged GET or POST request to the application.
This issue affects SOPlanning version 1.55 and below.
This issue affects SOPlanning version 1.55 and below.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-352
Source
NVD
Vendor
SOPlanning
Product
SOPlanning
Discussion (0)
Add Comment
No comments yet. Be the first!