S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated May 26, 2024

CVE-2024-33724 Scanner

CVE-2024-33724 scanner - Cross-Site Scripting (XSS) vulnerability in SOPlanning

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-33724
5.4
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

SOPlanning is a popular project management tool used by teams and organizations to plan and track their projects efficiently. It is widely used in corporate environments for scheduling and resource allocation. Developed for simplicity and effectiveness, SOPlanning allows administrators and users to collaborate and manage projects seamlessly. The platform supports multiple users and offers various features for task management and project tracking. It is used globally by project managers, team leaders, and other professionals to streamline their planning processes.

The vulnerability in SOPlanning v1.52.00 is a Cross-Site Scripting (XSS) flaw. It occurs due to improper validation of user input in the 'groupe_id' parameter. An unauthenticated attacker can exploit this vulnerability to inject malicious scripts. These scripts can hijack the admin or other user sessions, leading to potential account takeover.

The XSS vulnerability in SOPlanning v1.52.00 is found in the 'groupe_id' parameter. When a specially crafted script is injected into this parameter, it is executed in the context of the user's browser. The vulnerable endpoint is '/process/groupe_save.php', and the injection point is within the URL parameter. By manipulating this input, an attacker can execute arbitrary JavaScript code, which can capture sensitive information or perform unauthorized actions.

Exploitation of this XSS vulnerability can lead to severe consequences. An attacker could hijack user sessions, gaining unauthorized access to sensitive data. Admin accounts could be compromised, allowing the attacker to take over the entire platform. User credentials and session tokens might be stolen, leading to further unauthorized access and potential data breaches.

By becoming a member of the S4E platform, you gain access to a comprehensive suite of tools that safeguard your digital assets. Our platform provides continuous monitoring and detailed reports on vulnerabilities, ensuring you stay ahead of potential threats. Our easy-to-use interface and expert support help you mitigate risks effectively. Join us to secure your infrastructure and protect your organization from cyber threats with our state-of-the-art security solutions.

References:

Solution Advice
  • Validate and sanitize all user inputs, particularly those that are included in URL parameters.
  • Implement Content Security Policy (CSP) to restrict the execution of scripts on the site.
  • Regularly update and patch the SOPlanning software to include the latest security fixes.
  • Conduct regular security audits and code reviews to identify and address potential vulnerabilities.
  • Educate users and administrators about the risks of XSS and how to avoid them.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.