Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field. | |
| Title | Use of hard-coded credentials in Prospero Flow CRM employee onboarding | |
| First Time appeared |
Roskus
Roskus prospero Flow Crm |
|
| Weaknesses | CWE-798 | |
| CPEs | cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roskus
Roskus prospero Flow Crm |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Secur0
Published:
Updated: 2026-08-14T14:36:44.645Z
Reserved: 2026-08-14T12:22:02.795Z
Link: CVE-2026-19871
Updated: 2026-08-14T14:36:41.033Z
Status : Received
Published: 2026-08-14T14:16:51.493
Modified: 2026-08-14T15:17:09.207
Link: CVE-2026-19871
No data.
OpenCVE Enrichment
Updated: 2026-08-14T15:30:03Z