Article
Cyber News / Article / Vulnerability in SOPlanning software

CE
CERT Polska-2026-07-09
Vulnerability in SOPlanning software
CERT Polska has received a report about vulnerability in SOPlanning software and participated in coordination of its disclosure.
The vulnerabilityCVE-2026-50644: SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holdingparameters_allpermissions can inject SQL commands into the audit configuration form which is then saved. The execution is triggered when the audit functionality is accessed (by the attacker or another user).
This issue was fixed in version 1.56.01
We thank Arkadiusz Marta for the responsible vulnerability report.
Related articles
in
[email protected] (The Hacker News)Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
8 days ago
in
[email protected] (The Hacker News)Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
9 days ago
Io
Ionut ArghireSAP Patches Critical Extended Passport Processing Vulnerability
3 days ago
You might Also like

Gu
Guru Baran-2 days ago
Chrome 153 Fixes 230 Vulnerabilities, Including One 0-Day Exploited in the Wild

in
[email protected] (The Hacker News)-2 days ago
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

Gu
Guru Baran-2 days ago
