A vulnerability in Pantera CRM versions 401.152 and 402.072 allows unauthorized attackers to bypass IP-based access controls by manipulating the X-Forwarded-For header.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.