Beveiligingsadvies

CVE-2026-10850

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-17 14:39:51
Laatst bijgewerkt 2026-06-17 15:39:40
Toegewezen door Fluid Attacks
CVSS-score 6.9
Status PUBLISHED

Beschrijving

Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.