PT-2026-70206 · Roskus · Prospero Flow Crm
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Roskus Prospero Flow CRM versions prior to 5.4.9
Description
An authorization bypass exists in the ticket management component. Authenticated users can access, modify, or delete tickets belonging to other companies using the ticket's numeric identifier. This occurs because read and save operations do not restrict queries to the authenticated user's company. Additionally, the delete controller uses a generic
IlluminateHttpRequest instead of the TicketDeleteRequest, which fails to enforce necessary permissions. This allows users to read full ticket content (title, description, and attachments), hijack tickets by reassigning the company id variable, or delete tickets without authorization.Recommendations
Update Roskus Prospero Flow CRM to version 5.4.9 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prospero Flow Crm