Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
NextCRM has a BOLA/IDOR in PATCH /api/crm/contacts/[id] that allows Cross-Tenant CRM Data Tampering
Vulnerability Description
NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Level Authorization (BOLA/IDOR) vulnerability exists in the CRM contact and target update endpoints. The application fails to verify if the authenticated user has ownership of the specific resource being modified. This allows any authenticated user (even with a standard `member` role) to arbitrarily modify sensitive CRM contacts and targets belonging to other users or organizations (cross-tenant data tampering). Version 0.12.0 fixes the issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
pdovhomilja nextcrm-app 授权问题漏洞
Vulnerability Description
pdovhomilja nextcrm-app是pdovhomilja个人开发者的一款云计算客户关系管理应用程序。 pdovhomilja nextcrm-app 0.12.0之前版本存在授权问题漏洞,该漏洞源于对CRM联系人和目标更新端点的对象级授权(BOLA/IDOR)检查缺失,应用未能验证经过身份验证的用户是否对正在修改的特定资源具有所有权,可能导致任何经过身份验证的用户(即使是标准成员角色)任意修改属于其他用户或组织的敏感CRM联系人和目标(跨租户数据篡改)。
CVSS Information
N/A
Vulnerability Type
N/A