CVE-2026-82911 Cross-Site Request Forgery (CSRF) in the… — CVE Notify — TG.ME

🚨 CVE-2026-82911
Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/{order_number} in Roskus Prospero Flow CRM before 5.15.11 allows an unauthenticated attacker to confirm any order on behalf of an authenticated user by directing them to a crafted page. Laravel's VerifyCsrfToken middleware enforces CSRF tokens only on POST, PUT, PATCH, and DELETE requests; the Route::get declaration leaves this state-changing action unprotected. Session cookies configured with SameSite=Lax are automatically included in top-level cross-site navigation, so a single link click triggers OrderConfirmController::confirm() and transitions the target order from pending to confirmed without user authorization. Because order numbers are sequential integers, an attacker can enumerate and confirm all existing orders in a single automated sweep.

🎖@cveNotify
GitHub
fix(security): add CSRF protection to order confirmation endpoint (#265) · Roskus/prospero-flow-crm@a90c0c8
Changed the order confirmation endpoint from GET to POST to prevent CSRF attacks. GET requests bypass Laravel's CSRF middleware (VerifyCsrfToken only protects POST, PUT, PATCH, DELETE metho...
September 4, 2026 29 1