PT-2026-65087 · Roskus+1 · Prospero Flow Crm

·

CVE-2026-59239

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Roskus Prospero Flow CRM versions prior to 5.4.4
Description The email module contains a stored cross-site scripting issue. A remote, authenticated user with low privileges can execute arbitrary JavaScript in the browser of another user, including administrators, by storing a malicious payload in an email body. This occurs because the email body is persisted without sanitization and rendered unescaped using {!! $email->body !!} when the recipient opens the message, which can lead to session compromise and account takeover.
Recommendations Update Roskus Prospero Flow CRM to version 5.4.4 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59239

Affected Products

Prospero Flow Crm