Impact
OpenProject allows an IDOR where an authenticated user can move an agenda item to a section belonging to a different meeting. The flaw permits adding agenda items to meetings without giving the attacker direct access to those meetings, potentially causing confusion among participants.
Affected Systems
OpenProject, the open‑source project management platform published by opf, is affected. Any installation running a release older than version 17.0.2 inherits the flaw and is vulnerable.
Risk and Exploitability
The CVSS score is 4.3 and the EPSS indicates less than a 1 % likelihood of exploitation. The vulnerability does not appear in the CISA KEV catalog. The attack requires an authenticated user to interact with the drag‑and‑drop interface; no publicly known exploits exist, so the risk is primarily mitigated by applying the patch or restricting permissions.
OpenCVE Enrichment