Impact
An authenticated user can exploit an IDOR flaw in Plane’s estimate and comment endpoints, reading or updating estimates and injecting comments that belong to another workspace. The flaw stems from the API not verifying that the estimate or issue identifiers in the request path match the workspace and project specified in the URL. According to the CVE description, ProjectEntityPermission checks membership in the workspace and project from the URL, but the database look‑ups for estimate_id and issue_id ignore this context, permitting unauthorized access. This leads to confidentiality breaches, integrity violations, and untrusted input injection, as the attacker can create arbitrary comments in any workspace where the attacker holds a valid account. The identified weakness is CWE‑639, a classic Insecure Direct Object Reference scenario.
Affected Systems
The vulnerability affects the open‑source project management tool Plane from makeplane. All releases prior to version 1.4.0 are susceptible, including 1.3.x and earlier. Users running these affected versions without an upgrade are exposed.
Risk and Exploitability
The CVSS score of 8.7 classifies the issue as High severity, indicating significant impact if exploited. The EPSS score is not available, but the absence of a KEV listing does not diminish risk; the vulnerability requires only an authenticated user and an accessible endpoint, making exploitation relatively straightforward in environments where users have cross‑workspace privileges. The attack vector is inferred to be internal, as the victim must be an authenticated user who has some level of access across multiple workspaces. Given the simplicity of the request paths and the lack of client‑side protection, the likelihood of exploitation in active deployments is non‑negligible.
OpenCVE Enrichment