CVE-2025-48070 LOW

CVE-2025-48070: Plane has insecure permissions in UserSerializer

Vendor Makeplane
Product plane
Weakness CWE-276
Published May 21, 2025
Last update May 22, 2025

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer that allows users to change fields that are meant to be read-only, such as email. This can lead to account takeover when chained with another vulnerability such as cross-site scripting (XSS). Version 0.23 fixes the issue.

Key dates

02Disclosure timeline

May 21, 2025 CVE published
May 22, 2025 Record updated