Impact
The vulnerability allows an authenticated user of any company within Prospero Flow CRM to overwrite contact data belonging to another company and to export that contact’s personal information as a vCard. Because the save and export operations use the contact’s numeric identifier without verifying that the requesting user’s company matches the owner of the record, an attacker can blindly modify and disclose confidential data. This constitutes a bypass of authorization controls, leading to potential privacy violations and corruption of contact records.
Affected Systems
All installations of Roskus Prospero Flow CRM versions earlier than 5.4.8 are affected. The flaw exists in the contact management component and applies to the contact save and vCard export endpoints.
Risk and Exploitability
The CVSS score is 8.6, indicating a high‑severity vulnerability. The EPSS score is not available, but the flaw is not listed in the CISA KEV catalog. An attacker only needs to be authenticated within the CRM; the exploitation path involves supplying a legitimate contact identifier that belongs to a different company. Because the system is multi‑tenant, any authenticated user can impact records belonging to other tenants, increasing the overall risk to all users on the platform.
OpenCVE Enrichment