Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.
History

Tue, 07 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jan 2025 21:30:00 +0000

Type Values Removed Values Added
Description Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.
Title Plane has a Cross-site scripting (XSS) via SVG image upload
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-01-06T21:22:24.129Z

Updated: 2025-01-07T15:46:31.863Z

Reserved: 2024-12-29T03:00:24.713Z

Link: CVE-2025-21616

cve-icon Vulnrichment

Updated: 2025-01-07T15:46:12.588Z

cve-icon NVD

Status : Received

Published: 2025-01-06T22:15:11.023

Modified: 2025-01-07T16:15:40.390

Link: CVE-2025-21616

cve-icon Redhat

No data.