PT-2026-66780 · Roskus · Prospero Flow Crm
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Roskus Prospero Flow CRM versions prior to 5.3.7
Description
Authenticated users with permissions to create or update leads can execute arbitrary JavaScript within the application origin. This occurs in the lead index view when HTML markup stored in the lead name field is rendered using Blade's unescaped output directive and placed inside a JavaScript string literal within an
onclick attribute.Recommendations
Update Roskus Prospero Flow CRM to version 5.3.7 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prospero Flow Crm