漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation
Vulnerability Description
Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to create payroll records attributed to another company's employees, because the listing query is not scoped to the caller's company and the employee identifier is validated for global existence rather than company membership
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
roskus Prospero Flow CRM 授权问题漏洞
Vulnerability Description
roskus Prospero Flow CRM是roskus组织开源的一款客户关系管理软件。 roskus Prospero Flow CRM 5.15.10之前版本存在授权问题漏洞,该漏洞源于payroll模块中列表查询未限定调用方公司且员工标识符仅验证全局存在性而非公司成员资格,可能导致持有读取工资权限的认证用户查看其他公司员工的工资和银行详细信息,或持有创建工资权限的用户创建归属其他公司员工的工资记录。
CVSS Information
N/A
Vulnerability Type
N/A