Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4fxp-2m36-qv64

Опубликовано: 10 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their own, the complete set of application permissions via a crafted POST request to the permission save endpoint, which performs no authorization check before synchronizing the submitted permissions to the specified role.

Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their own, the complete set of application permissions via a crafted POST request to the permission save endpoint, which performs no authorization check before synchronizing the submitted permissions to the specified role.

EPSS

Процентиль: 15%
0.00238
Низкий

8.7 High

CVSS4

Дефекты

CWE-639

Связанные уязвимости

nvd
17 дней назад

Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their own, the complete set of application permissions via a crafted POST request to the permission save endpoint, which performs no authorization check before synchronizing the submitted permissions to the specified role.

EPSS

Процентиль: 15%
0.00238
Низкий

8.7 High

CVSS4

Дефекты

CWE-639