Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking
Vulnerability Description
Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated users of any company to read the full sensitive data (price, cost, stock, SKU, and barcode) of another company's product and to hijack that product by reassigning its company_id, via the product's numeric identifier, because `ProductUpdateController` did not extend `MainController` and therefore required no authentication check on the read endpoint, and `ProductRepository::save()` retrieved the record via `Product::find($data['id'])` without constraining the query to the authenticated user's company before overwriting its company_id.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Roskus Prospero Flow CRM 授权问题漏洞
Vulnerability Description
Roskus Prospero Flow CRM是Roskus组织开源的一款客户关系管理软件 Roskus Prospero Flow CRM 5.4.7之前版本存在授权问题漏洞,该漏洞源于产品管理组件缺少授权及用户可控密钥的授权绕过,可能导致任何公司的认证用户读取其他公司产品的敏感数据(价格、成本、库存、SKU和条形码),并通过重新分配company_id劫持该产品。
CVSS Information
N/A
Vulnerability Type
N/A