PT-2026-65087 · Roskus+1 · Prospero Flow Crm
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Roskus Prospero Flow CRM versions prior to 5.4.4
Description
The email module contains a stored cross-site scripting issue. A remote, authenticated user with low privileges can execute arbitrary JavaScript in the browser of another user, including administrators, by storing a malicious payload in an email body. This occurs because the email body is persisted without sanitization and rendered unescaped using
{!! $email->body !!} when the recipient opens the message, which can lead to session compromise and account takeover.Recommendations
Update Roskus Prospero Flow CRM to version 5.4.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prospero Flow Crm