在 Roskus Prospero Flow CRM 4.9.1 至 5.14.0 版本中,交易保存端点(/transaction/save)存在通过用户可控键值绕过授权检查的漏洞。具备交易创建和会计创建权限的用户,可以通过向 POST /transaction/save 提交属于其他公司的 bank_account_id 或 bank_card_id,从而泄露该公司银行账户名称、银行名称以及银行卡后四位数字。由于该请求在持久化及渲染过程中未对公司所有权进行任何校验,导致攻击者能够越权访问非本公司敏感的银行账户信息
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Roskus | Prospero Flow CRM | 4.9.1< 5.14.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Roskus | Prospero Flow CRM | 4.9.1 ~ 5.14.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet