Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59233

Опубликовано: 10 авг. 2026
Источник: nvd
EPSS Низкий

Описание

Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their own, the complete set of application permissions via a crafted POST request to the permission save endpoint, which performs no authorization check before synchronizing the submitted permissions to the specified role.

EPSS

Процентиль: 15%
0.00238
Низкий

Дефекты

CWE-639

Связанные уязвимости

github
17 дней назад

Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their own, the complete set of application permissions via a crafted POST request to the permission save endpoint, which performs no authorization check before synchronizing the submitted permissions to the specified role.

EPSS

Процентиль: 15%
0.00238
Низкий

Дефекты

CWE-639