CyberRota Analysis
AI-GeneratedThe ProjectMemberViewSet.partial_update method in Plane, prior to version 1.3.0, allows users with the GUEST role to modify the roles of other project members, potentially demoting Administrators and Members. This flaw can severely impact project control and security, making it critical for organizations using this project management tool to upgrade to version 1.3.0 immediately to mitigate the risk. All users of the affected versions should prioritize this update to protect their project integrity.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0.