Executive brief
Prospero Flow CRM, a customer relationship management platform, contains a security flaw that allows users to delete calendar events belonging to other people or companies. By simply changing the ID number in a specific web link, an authenticated user can permanently remove data they do not own. This could lead to significant data loss and disruption of business schedules across the entire platform.
Technical details
An Authorization Bypass Through User-Controlled Key (CWE-639), also known as IDOR, exists in the CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php). The application exposes a deletion endpoint at GET /calendar/event/delete/{id} which uses the Eloquent find($id)->delete() method without verifying if the authenticated user owns the record or belongs to the same company. An attacker can iterate through ID values to delete events across different tenants. The vulnerability was addressed in version 5.5.3 by implementing ownership scoping (user_id and company_id checks) before executing the delete command.
Affected products
- Roskus Prospero Flow CRM before 5.5.3
Timeline
- 2026-06-25: patched: Fix committed to repository
- 2026-06-26: advisory: Release v5.5.3 published
- 2026-07-03: disclosed: CVE published to NVD
References
- https://github.com/Roskus/prospero-flow-crm
- https://github.com/Roskus/prospero-flow-crm/commit/8c26eed4d80544c30e55448e12a8e999af6d2b70
- https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3
- https://secur0.com/en/cna/cve-list/cve-2026-59234-idor-in-prospero-flow-crm-allows-deletion-of-other-users-calendar-events