Beaussier develops a narrowly scoped room-planning and management application, RoomPHPlanning, that presents a focused but recurring vulnerability surface in web-based application logic. The vendor's disclosures cluster around input-validation and authentication weaknesses—specifically SQL injection and improper authentication mechanisms—that are characteristic of PHP-based administrative and scheduling systems, and frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Beaussier over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4671HIGH Login.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by setting the room_phplanning cookie to a value associated with t | Mar 5, 2010 | 7.5 | 28 | NO | YES |
CVE-2009-4670HIGH admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user parameter or (2) delete arbitrary | Mar 5, 2010 | 7.5 | 28 | NO | YES |
CVE-2009-4669HIGH Multiple SQL injection vulnerabilities in RoomPHPlanning 1.6 allow remote attackers to execute arbitrary SQL commands via (1) the loginus parameter to Login.php or (2) the Old Pass | Mar 5, 2010 | 7.5 | 28 | NO | YES |
CVE-2008-6634HIGH SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idroom parameter to weekview.php. | Apr 7, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6633HIGH SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idresa parameter to resaopen.php. | Apr 7, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-2488MEDIUM admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin accounts. | May 28, 2008 | 6.5 | 27 | NO | YES |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Beaussier.
Media articles that mention a CVE ID that affects a product developed by Beaussier — matched by CVE ID, not by vendor name.