What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in Propovoice Propovoice CRM.This issue affects Propovoice CRM: from n/a through 1.7.6.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in Propovoice Propovoice CRM.This issue affects Propovoice CRM: from n/a through 1.7.6.4.
Explanation of Vulnerability in Simple Terms
Propovoice CRM versions up to 1.7.6.4 contain an authorization flaw that allows unauthenticated attackers to read sensitive information over the network. The vulnerability requires no user interaction and can be exploited remotely. No authentication is needed to trigger the issue.
What an attacker can do
Read sensitive information from the CRM without logging in.
Potential impact on your site
Confidential CRM data may be exposed to unauthorized parties without any warning or user action.
Conditions required to exploit
Network access to the Propovoice CRM instance. No authentication required.
Key dates
External resources
Related vulnerabilities