Impact
The vulnerability is an IDOR that allows any authenticated ProjectMember, including Guests, to read the member roster of any private project within the same workspace. An attacker can harvest personal information such as email addresses, names, avatars, and roles, exposing sensitive user data. The flaw arises because ProjectMemberListCreateAPIEndpoint only verifies that the caller is a ProjectMember of any project in the workspace but does not bind the check to the project_id supplied in the URL, enabling cross‑project data disclosure. CWE‑862 – Broken Access Control applies.
Affected Systems
The affected product is Plane from makeplane. Versions older than 1.4.0 contain the flaw; the issue is fixed in release 1.4.0. Any workspace where a user holds ProjectMember status in at least one project is vulnerable.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated credentials within the target workspace and two HTTP requests: a GET to the affected endpoint with an arbitrary project_id. The missing project scope allows an attacker to easily read private roster data with moderate effort, presenting a moderate risk until the fix is applied.
OpenCVE Enrichment