Vulnerability Details CVE-2023-30791
Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.8%
CVSS Severity
CVSS v3 Score 7.1
Products affected by CVE-2023-30791
-
cpe:2.3:a:plane:plane:0.7.1