← Back to CVE List

CVE-2024-57170

Published: 2025-03-18T16:15Z
Last Modified: 2025-04-02T12:29Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attackers to specify file paths containing directory traversal sequences (e.g., ../). This vulnerability enables attackers to delete arbitrary files outside the intended upload directory, potentially leading to denial of service or disruption of application functionality. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt