Home

Description

Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer that allows users to change fields that are meant to be read-only, such as email. This can lead to account takeover when chained with another vulnerability such as cross-site scripting (XSS). Version 0.23 fixes the issue.

PUBLISHED Reserved 2025-05-15 | Published 2025-05-21 | Updated 2025-05-22 | Assigner GitHub_M




LOW: 3.5CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Problem types

CWE-276: Incorrect Default Permissions

Product status

< 0.23
affected

References

github.com/.../plane/security/advisories/GHSA-cjh4-q763-cc48 exploit

github.com/.../plane/security/advisories/GHSA-cjh4-q763-cc48

github.com/...ommit/0a8cc24da505fd519fcc3c9d6b5e15bc7ce21b29

cve.org (CVE-2025-48070)

nvd.nist.gov (CVE-2025-48070)

Download JSON