CVE-2014-8674

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
06/01/2020
Last modified:
10/01/2020

Description

Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET parameter to export.php, which allows malicious users to execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*:* 1.33 (excluding)