PT-2026-106034 · Plane · Plane
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Plane versions prior to 1.4.0
Description
Two endpoint families fail to verify that nested resource identifiers belong to the workspace and project specified in the URL. An authenticated user can read or modify estimates from another workspace via the PATCH '/api/workspaces/{slug}/projects/{project id}/estimates/{estimate id}/' endpoint, or inject comments into an issue from another workspace via the POST '/api/workspaces/{slug}/projects/{project id}/issues/{issue id}/comments/' endpoint. While the
ProjectEntityPermission function verifies membership in the workspace and project from the URL, the estimate id and issue id variables are fetched by primary key without confirming the same scope.Recommendations
Update to version 1.4.0.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plane