漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Authorization Bypass Through User-Controlled Key in Prospero Flow CRM contact save and vCard export
Vulnerability Description
Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated users of any company to blindly overwrite the contact data of another company and to download that contact's personal data as a vCard via the contact's numeric identifier, because the save and export operations retrieve the record without constraining the query to the authenticated user's company.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
roskus Prospero Flow CRM 授权问题漏洞
Vulnerability Description
roskus Prospero Flow CRM是roskus组织开源的一款客户关系管理软件。 roskus Prospero Flow CRM 5.4.8之前版本存在授权问题漏洞,该漏洞源于contact management组件存在用户控制密钥的授权绕过问题,保存和导出操作在检索记录时未将查询限制为认证用户所属公司,导致任意公司的认证用户可覆盖其他公司的联系人数据,并通过联系人数字标识符下载该联系人的个人数据。
CVSS Information
N/A
Vulnerability Type
N/A