CVE detail
CVE-2014-8677 — CVE-2014-8677
Published 2017-08-31 · Modified 2026-06-17 · Vendor soplanning · Product soplanning · Source nvd
MEDIUM
severity
CVSS-derived band
0.0349
EPSS probability
exploitation probability, 30d
88.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2 is being used, the configuration database is down, and smarty/templates_c is not writable to execute arbitrary php code via a crafted database name.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References