CyberRota Analysis
AI-GeneratedThe vulnerability allows authenticated attackers to exploit the public comment endpoint in Plane through version 1.4.2, enabling them to post comments to arbitrary issues by manipulating the issue_id parameter. This could lead to unauthorized information disclosure or misinformation across workspaces. Organizations using this version of Plane should prioritize remediation to mitigate potential impacts on project integrity and security.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to the public deploy-board comment endpoint.