Authorization Bypass Through User-Controlled Key (CWE-639...
Moderate severity
Unreviewed
Published
Jul 16, 2026
to the GitHub Advisory Database
•
Updated Jul 16, 2026
Description
Published by the National Vulnerability Database
Jul 16, 2026
Published to the GitHub Advisory Database
Jul 16, 2026
Last updated
Jul 16, 2026
Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 allows a remote, authenticated user to read, modify, and delete orders and order items belonging to any other company (tenant) via a sequential numeric {id} supplied to GET /api/order/{id}, PUT /api/order/{id}, GET /api/order-item/{id}, PUT /api/order-item/{id}, or DELETE /api/order-item/{id}, because the controllers resolve records with Order::find($id) / Item::find($id) without scoping by the authenticated user's company.
References