PT-2026-72025 · Roskus · Prospero Flow Crm
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Roskus Prospero Flow CRM versions prior to 5.15.9
Description
The human resources component contains hard-coded credentials. Unauthenticated remote attackers can authenticate as any employee onboarded through the standard flow by providing only the employee's email address. This occurs because the employee save controller defaults to the password
changeme and the onboarding form does not include a password field.Recommendations
Update Roskus Prospero Flow CRM to version 5.15.9 or later.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prospero Flow Crm