PT-2023-22984 · Plane · Plane
Lautaro Casanova
·
Published
2023-07-15
·
Updated
2023-07-28
·
CVE-2023-30791
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Plane version 0.7.1-dev
Description
The issue allows an attacker to change the avatar of their profile, enabling the upload of files with HTML extension that can interpret both HTML and JavaScript.
Recommendations
For Plane version 0.7.1-dev, consider disabling the avatar upload feature until a patch is available to prevent exploitation. Restrict access to profile modification to minimize the risk of malicious file uploads. Avoid using the feature that allows HTML file uploads in the affected version until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plane