4.6
CVSSv3

CVE-2023-30791

Published: 15/07/2023 Updated: 28/07/2023
CVSS v3 Base Score: 4.6 | Impact Score: 2.5 | Exploitability Score: 2.1
VMScore: 0

Vulnerability Summary

Plane version 0.7.1-dev allows an malicious user to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript.

Vulnerable Product Search on Vulmon Subscribe to Product

plane plane 0.7.1