Horizon Alert
Summary of the vulnerability and why it matters
This advisory addresses a critical vulnerability in WACRM, a self-hostable CRM template for WhatsApp, that could allow authenticated users to gain unauthorized access and modify data within other tenants. The issue stems from flawed access control policies within the database's security configurations. While specific business impact is uncertain without knowing deployment specifics, the potential for data compromise warrants attention.
- Unauthorized access and data modification risks.
- Affects self-hosted WhatsApp CRM templates.
- Confirm relevance and assess potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker with existing access to WACRM could exploit this vulnerability by crafting specific requests to manipulate user roles or access sensitive data. The attacker would first need to authenticate as a regular user. By targeting a flawed security policy or a function that bypasses member checks, they could then elevate their privileges or view data belonging to other tenants, potentially leading to unauthorized modification or exposure of tenant resources and AI knowledge.
- Authenticated user required for access.
- Manipulate roles or bypass access checks.
- Unauthorized data access and modification.
Live Threat
Current exploitation, exposure, and threat context
Authenticated users of WACRM could gain unauthorized access to or modify another tenant's data. This is possible when specific database policies are bypassed, allowing users to self-promote or change their tenant affiliation. This could lead to unauthorized viewing or alteration of sensitive customer information within different accounts.
- Tenant data and user roles.
- Authenticated users can exploit policy flaws.
- Unauthorized access and modification of data.
Operational Fix
Recommended remediation, mitigation, and detection steps
Determining ownership for WACRM, a self-hostable WhatsApp CRM template, requires understanding its deployment. Application owners are likely responsible for the core CRM functionality, while infrastructure or platform teams may manage the underlying Supabase or hosting environment. The first step is to identify all WACRM instances, assess their exposure and criticality, and then engage the accountable owners to plan remediation.
- Application owners, platform teams.
- Confirm instance reachability and criticality.
- Plan maintenance, coordinate with vendors.