CVE-2014-8674 describes multiple Cross-Site Scripting (XSS) vulnerabilities in Simple Online Planning (SOPlanning) versions prior to 1.33. Specifically, these flaws allow malicious users to execute arbitrary code through manipulated document.cookie values in 'nb_mois' and 'mb_ligness', and via the 'debug' GET parameter in 'export.php'. Rated with a CVSS score of 5.4 (Medium), this vulnerability requires low privileges and user interaction, but can lead to low impact on confidentiality and integrity. The attack vector is network-based, indicating it can be exploited remotely. While not listed on the KEV catalog or Hot List, an ExploitDB entry (EDB-37604) confirms the existence of exploit code. There is no evidence of active exploitation, and community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.33CPE matchmatch criteria | cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.