Roskus Prospero Flow CRM 版本 4.0.0 至 5.3.1 中的供应商 API 存在通过用户可控密钥绕过授权控制的漏洞。攻击者只需向 /api/supplier/{id} 发送 PUT 请求,并在请求体中设置 company_id 字段,即可在已认证用户的情况下,读取和修改其他公司的供应商记录,并将其重新分配至自己的公司。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Roskus | Prospero Flow CRM | 4.0.0< 5.3.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Roskus | Prospero Flow CRM | 4.0.0 ~ 5.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet