« Volver al listado

Roskus

Roskus Prospero Flow CRM: vulnerabilidades y CVE

Roskus Prospero Flow CRM tiene 15 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE15
Últimos 12 meses15
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-82911Media (5.1)0.23%—4 sept 2026
Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/{order_number} in Roskus Prospero Flow CRM before 5.15.11 allows an unauthenticated attacker to confirm any order on behalf of an…
CVE-2026-81931Media (4.8)0.48%—27 ago 2026
Unrestricted Upload of File with Dangerous Type in the product photo upload in Roskus Prospero Flow CRM before 5.16.0 allows an authenticated user holding the create product permission (routine Seller role) to execute…
CVE-2026-78365Crítica (9.3)0.51%—24 ago 2026
Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it…
CVE-2026-78337Media (4.8)0.40%—24 ago 2026
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute…
CVE-2026-77759Alta (8.7)0.51%—21 ago 2026
Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the same instance via…
CVE-2026-19871Crítica (9.3)0.53%—14 ago 2026
Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow,…
CVE-2026-19870Alta (8.6)0.39%—14 ago 2026
Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of…
CVE-2026-19734Alta (8.6)0.59%—13 ago 2026
Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated users of any company to read the full…
CVE-2026-19539Alta (8.6)0.44%—11 ago 2026
Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title, description, and…
CVE-2026-19433Alta (8.6)0.44%—10 ago 2026
Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated users of any company to blindly overwrite the contact data of another…
CVE-2026-59233Alta (8.7)0.41%—10 ago 2026
Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their own, the complete set of application permissions via…
CVE-2026-59232Media (5.3)0.53%—31 jul 2026
Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via…
CVE-2026-59239Alta (8.6)0.67%—27 jul 2026
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including…
CVE-2026-59237Media (6.9)0.64%—16 jul 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 allows a remote, authenticated user to read, modify, and delete orders…
CVE-2026-59236Media (6.9)0.64%—15 jul 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated user of any…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services5
  2. T1005 Data from Local System3
  3. T1190 Exploit Public-Facing Application3
  4. T1078 Valid Accounts2
  5. T1059.007 JavaScript1
  6. T1078.001 Default Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.