PT-2026-79384 · Roskus · Prospero Flow Crm
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Roskus Prospero Flow CRM versions 4.9.1 through 5.14.0
Description
An authorization bypass exists in the transaction save endpoint. A user with transaction and accounting creation permissions can disclose sensitive banking information from another company, including the bank account name, bank name, and the last four digits of a card. This occurs when a
bank account id or bank card id belonging to another company is provided in the POST '/transaction/save' endpoint, as the system persists and renders the data without verifying company ownership.Recommendations
Update Roskus Prospero Flow CRM to a version later than 5.14.0.
As a temporary mitigation, restrict user permissions for transaction and accounting creation to trusted personnel only.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prospero Flow Crm