CVE-2025-62730
Last modified
CVE-2025-62730 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This allow a malicious authenticated attacker with this role to escalate to admin privileges. This issue affects both Bulk Update functionality and regular edition of user's right and privileges. This issue was fixed in version 1.55.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Soplanning | Soplanning | < 1.55.00 |
References
- https://cert.pl/en/posts/2025/11/CVE-2025-62293Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-62730?
How severe is CVE-2025-62730?
How do I fix CVE-2025-62730?
Are you affected by CVE-2025-62730?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
