PT-2026-47450 · Wacrm · Wacrm
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
WACRM versions prior to commit 73041bf
Description
An authorization bypass exists in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants. By providing an arbitrary
contact id in the body of a 'POST' request, attackers can bypass tenant ownership verification. This is achieved by exploiting the service-role client, which bypasses row-level security (a security feature that restricts which rows of data a user can see or modify based on their identity), enabling the modification of victim contact fields such as name, email, and company across tenant boundaries using a known contact UUID.Recommendations
Update WACRM to commit 73041bf or a later version.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wacrm