Impact
Authorization bypass occurs through a user‑controlled key; any authenticated user can read and alter another company’s supplier record, including reassigning it to their own company, by sending a PUT request to /api/supplier/{id} with a new company_id. The vulnerability allows unauthorized disclosure of supplier details and the manipulation of vendor relationships, potentially affecting procurement, billing, and compliance processes.
Affected Systems
The flaw exists in Roskus Prospero Flow CRM, specifically in versions 4.0.0 through 5.3.1 inclusive. It targets the supplier API endpoint that is shared across tenants, allowing cross‑tenant access to supplier data.
Risk and Exploitability
The CVSS score of 9.3 signals a critical severity. EPSS is not available, but the vulnerability does not require any special conditions beyond having valid credentials for the target tenant. Once an attacker authenticates, they can perform read or write operations on any supplier record. The issue is not yet listed in CISA’s KEV catalog, but the potential for widespread data compromise across multiple organizations makes this a high‑risk exposure.
OpenCVE Enrichment