漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Missing Authorization in Prospero Flow CRM permission save endpoint allows privilege escalation
Vulnerability Description
Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their own, the complete set of application permissions via a crafted POST request to the permission save endpoint, which performs no authorization check before synchronizing the submitted permissions to the specified role.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Roskus Prospero Flow CRM 授权问题漏洞
Vulnerability Description
roskus Prospero Flow CRM是roskus组织开源的一款客户关系管理软件。 Roskus Prospero Flow CRM 5.2.1之前版本存在授权问题漏洞,该漏洞源于权限管理组件缺失授权,通过向权限保存端点发送特制POST请求,未执行授权检查即同步提交的权限,可能导致任何已认证用户授予任何角色(包括自己的角色)完整的应用程序权限。
CVSS Information
N/A
Vulnerability Type
N/A