PT-2026-72014 · Roskus · Prospero Flow Crm
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Roskus Prospero Flow CRM versions prior to 5.15.10
Description
An authorization bypass exists in the payroll module where the listing query is not scoped to the caller's company and the employee identifier is validated for global existence rather than company membership. This allows authenticated users with read payroll permissions to view salary and banking details of employees from any other company within the instance. Additionally, users with create payroll permissions can create payroll records attributed to employees of other companies.
Recommendations
Update Roskus Prospero Flow CRM to version 5.15.10 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prospero Flow Crm