CVE-2026-40544

SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a malicious user.csv file with embedded JavaScript. The injected code is executed in the victim’s browser when a user clicks the Edit button for the malicious backup. This issue affects SOPlanning version 1.55 and below.
CVSS

No CVSS.

Configurations

No configuration.

History

22 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) SOPlanning es vulnerable a Cross-Site Scripting Almacenado (XSS) a través del endpoint /process/upload_backup. Un atacante autenticado con acceso a la funcionalidad de copia de seguridad puede subir un archivo ZIP manipulado que contiene un archivo user.csv malicioso con JavaScript incrustado. El código inyectado se ejecuta en el navegador de la víctima cuando un usuario hace clic en el botón Editar para la copia de seguridad maliciosa. Este problema afecta a SOPlanning versión 1.55 y anteriores.

01 Jun 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 09:16

Updated : 2026-07-22 07:10


NVD link : CVE-2026-40544

Mitre link : CVE-2026-40544

CVE.ORG link : CVE-2026-40544


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')