Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project members role. The authorization check prevents assigning a role higher than the requesters role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrators and Members and deny them project control. This vulnerability is fixed in 1.3.0.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.