跨站请求伪造(CSRF)漏洞:Roskus Prospero Flow CRM 5.15.11 之前版本中 OrderConfirmController 的 GET /order/confirm/{order_number} 在 Roskus Prospero Flow CRM 5.15.11 之前版本中, 中处理 的路由存在跨站请求伪造(CSRF)漏洞,允许未认证的攻击者通过引导已认证用户访问一个精心构造的页面,代表该用户确认任意订单。 Laravel 的 中间件仅在 POST、PUT、PATCH 和 DELET
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Roskus | Prospero Flow CRM | < 5.15.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Roskus | Prospero Flow CRM | 0 ~ 5.15.11 |
cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet