PT-2026-69482 · Roskus · Prospero Flow Crm
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Roskus Prospero Flow CRM versions prior to 5.2.1
Description
The permission management component contains a flaw where the permission save endpoint does not perform authorization checks. This allows any authenticated user to grant any role, including their own, the full set of application permissions by sending a crafted POST request to the endpoint, which then synchronizes the submitted permissions to the specified role.
Recommendations
Update to version 5.2.1 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prospero Flow Crm