PT-2026-60108 · Roskus+1 · Prospero Flow Crm
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Roskus Prospero Flow CRM versions prior to 5.14.0
Description
An authorization bypass exists in the Excel import handlers (CustomerImport, LeadImport, and ProductImport). A remote, authenticated user can create customer, lead, and product records within another company's tenant by uploading a spreadsheet to the POST '/customer/import/excel/save' endpoint. The system maps the
company id variable directly from the uploaded file without verifying if it matches the authenticated user's company, allowing the company id to be controlled by the user.Recommendations
Update Roskus Prospero Flow CRM to version 5.14.0 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prospero Flow Crm