PT-2026-80862 · Roskus · Prospero Flow Crm
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Roskus Prospero Flow CRM versions 4.0.0 through 5.3.1
Description
An authorization bypass exists in the supplier API that allows an authenticated user to read, modify, and reassign supplier records belonging to other companies to their own. This is achieved by sending a PUT request to the '/api/supplier/{id}' endpoint and manipulating the
company id variable within the request body.Recommendations
Update Roskus Prospero Flow CRM to a version later than 5.3.1.
Restrict the use of the
company id parameter in the '/api/supplier/{id}' endpoint to prevent unauthorized record reassignment.Exploit
Fix
Missing Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Prospero Flow Crm