CVE-2024-48536: Esoftplanner Esoft Planner

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request.

Affected products

Published 2024-11-20. Last modified 2026-06-17.