CyberRota Analysis
AI-GeneratedThe human resources component in Roskus Prospero Flow CRM prior to version 5.15.9 is vulnerable due to hard-coded credentials, allowing unauthenticated remote attackers to gain access as any employee by simply knowing their email address. This critical vulnerability poses a significant risk of unauthorized access to sensitive employee information and systems. Organizations using this CRM should prioritize immediate updates to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field.