Retour à la veille

CVE-2026-77759

Publié : 21 août 2026
Modifié : 21 août 2026
Lien officiel NVD

Description détaillée

Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the same instance via an incremented identifier in GET /api/transaction/{id}, which is resolved without company scoping and without any permission check.

Références et Patchs