Impact
The vulnerability resides in the permission management component of Prospero Flow CRM, where a POST request to the permission save endpoint lacks an authorization check. An authenticated user can issue a crafted request to assign any role, including their own, with the complete set of application permissions, effectively elevating privileges without constraint. This flaw enables simple credential escalation and could grant unrestricted access to sensitive data and administrative controls.
Affected Systems
The flaw affects all versions of Roskus Prospero Flow CRM prior to 5.2.1. Users should upgrade to version 5.2.1 or newer to eliminate the missing authorization check.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. While an EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation yet. An attacker needs to be authenticated to the system but can then leverage the exposed endpoint to gain administrative privileges, which suggests a straightforward exploit path against any deployed instance lacking the patch.
OpenCVE Enrichment