Insecure Permissions in Plane Project Management Software
CVE-2025-48070
4.3MEDIUM
What is CVE-2025-48070?
The Plane open-source project management software has a vulnerability that stems from insecure permissions in the UserSerializer component. This flaw allows unauthorized users to modify fields that should remain read-only, including sensitive information like email addresses. If exploited, an attacker could potentially escalate this vulnerability in conjunction with other weaknesses, such as cross-site scripting (XSS), leading to unauthorized account access. Users are advised to upgrade to version 0.23 or later, where these security concerns have been addressed.
Affected Version(s)
plane < 0.23
