Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade to version 5.4.8 or higher.
Workaround
No workaround given by the vendor.
Mon, 10 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated users of any company to blindly overwrite the contact data of another company and to download that contact's personal data as a vCard via the contact's numeric identifier, because the save and export operations retrieve the record without constraining the query to the authenticated user's company. | |
| Title | Authorization Bypass Through User-Controlled Key in Prospero Flow CRM contact save and vCard export | |
| First Time appeared |
Roskus
Roskus prospero Flow Crm |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roskus
Roskus prospero Flow Crm |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Secur0
Published:
Updated: 2026-08-10T17:53:38.907Z
Reserved: 2026-08-10T12:41:19.273Z
Link: CVE-2026-19433
Updated: 2026-08-10T17:53:33.558Z
Status : Received
Published: 2026-08-10T15:17:43.330
Modified: 2026-08-10T18:17:43.030
Link: CVE-2026-19433
No data.
OpenCVE Enrichment
Updated: 2026-08-11T04:15:02Z