Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

K1Di3

#20323of 56,330
14Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-69482
8.7
2026-08-10
Roskus · Prospero Flow Crm · CVE-2026-59233
**Name of the Vulnerable Software and Affected Versions** Roskus Prospero Flow CRM versions prior to 5.2.1 **Description** The permission management component contains a flaw where the permission save endpoint does not perform authorization checks. This allows any authenticated user to grant any role, including their own, the full set of application permissions by sending a crafted POST request to the endpoint, which then synchronizes the submitted permissions to the specified role. **Recommendations** Update to version 5.2.1 or later.
PT-2026-66780
5.3
2026-07-31
Roskus · Prospero Flow Crm · CVE-2026-59232
**Name of the Vulnerable Software and Affected Versions** Roskus Prospero Flow CRM versions prior to 5.3.7 **Description** Authenticated users with permissions to create or update leads can execute arbitrary JavaScript within the application origin. This occurs in the lead index view when HTML markup stored in the lead name field is rendered using Blade's unescaped output directive and placed inside a JavaScript string literal within an `onclick` attribute. **Recommendations** Update Roskus Prospero Flow CRM to version 5.3.7 or later.