Horizon Alert
Summary of the vulnerability and why it matters
This critical vulnerability affects a customer relationship management system's supplier API, allowing any authenticated user to access and modify another company's supplier records. At a high level, this could lead to unauthorized data manipulation and a disruption of business operations.
- Any user can change other companies' supplier data.
- Critical CRM flaw impacts data integrity and business operations.
- Confirm relevance and assess exposure for business continuity.
Attack Path
How an attacker could exploit the issue
An attacker with any authenticated user account could exploit this vulnerability by sending a specially crafted request to the supplier API. This request would target a specific supplier record and include a modified company ID, effectively allowing the attacker to view, change, or reassign another company's supplier information to their own.
- Requires authenticated user access.
- Triggered via a PUT request to the supplier API.
- Risk of unauthorized data modification and reassignment.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, any authenticated user could potentially access and modify supplier records belonging to other companies within the Roskus Prospero Flow CRM. This occurs when an authenticated user makes a PUT request to the supplier API, specifying a different company ID in the request body.
- Company supplier data.
- Via PUT request to supplier API.
- Unauthorized data modification and reassignment.
Operational Fix
Recommended remediation, mitigation, and detection steps
The supplier API in Roskus Prospero Flow CRM is likely managed by the application or platform team responsible for the CRM's functionality and deployment. The first practical move is to identify all instances of this CRM, determine their exposure and criticality, and confirm the accountable owner for each. Remediation planning should then be based on this risk assessment.
- Application or platform team owns the issue.
- Verify CRM instances and exposure.
- Plan remediation based on risk.