Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-35153 | Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2024-10-30T15:19:28.239Z
Reserved: 2023-04-17T13:24:41.354Z
Link: CVE-2023-30791
Updated: 2024-08-02T14:37:15.390Z
Status : Modified
Published: 2023-07-15T19:15:09.587
Modified: 2024-11-21T08:00:54.737
Link: CVE-2023-30791
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD