漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking
Vulnerability Description
Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated users of any company to read the full sensitive data (price, cost, stock, SKU, and barcode) of another company's product and to hijack that product by reassigning its company_id, via the product's numeric identifier, because `ProductUpdateController` did not extend `MainController` and therefore required no authentication check on the read endpoint, and `ProductRepository::save()` retrieved the record via `Product::find($data['id'])` without constraining the query to the authenticated user's company before overwriting its company_id.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Roskus Prospero Flow CRM 授权问题漏洞
Vulnerability Description
Roskus Prospero Flow CRM是Roskus组织开源的一款客户关系管理软件 Roskus Prospero Flow CRM 5.4.7之前版本存在授权问题漏洞,该漏洞源于产品管理组件缺少授权及用户可控密钥的授权绕过,可能导致任何公司的认证用户读取其他公司产品的敏感数据(价格、成本、库存、SKU和条形码),并通过重新分配company_id劫持该产品。
CVSS Information
N/A
Vulnerability Type
N/A