CVE Details
Basic Information
| Title |
CVE-2025-48070 |
| Type |
cve |
| Published |
2025-05-21T22:15:51 |
| Last Seen |
2025-05-21T22:25:45 |
CVSS Information
| Base Score |
3.5 (LOW) |
| Attack Vector |
NETWORK |
| Attack Complexity |
LOW |
| Privileges Required |
LOW |
| User Interaction |
REQUIRED |
| Scope |
UNCHANGED |
| Confidentiality Impact |
NONE |
| Integrity Impact |
LOW |
| Availability Impact |
NONE |
AI Analysis
| AI Description |
Plane, an open-source project management tool, has a vulnerability where versions prior to 0.23 allow users to modify read-only fields like email due to insecure permissions in UserSerializer. |
| AI Severity |
Low |
| Vendor |
Plane Community |
| Product |
Plane |
| Affected Version |
Prior to 0.23 |
Additional Information
| CVE List |
CVE-2025-48070 |
| CWE List |
CWE-276 |
| Bulletin Family |
cve |
Description
Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer that allows users to change fields that are meant to be read-only, such as email. This can…
CVSS Score Summary
Base Score: %!f(string=#) (LOW)
View Full CVE Details