PT-2026-66780 · Roskus · Prospero Flow Crm

·

CVE-2026-59232

·

Published

2026-07-31

·

Updated

2026-07-31

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Roskus Prospero Flow CRM versions prior to 5.3.7
Description Authenticated users with permissions to create or update leads can execute arbitrary JavaScript within the application origin. This occurs in the lead index view when HTML markup stored in the lead name field is rendered using Blade's unescaped output directive and placed inside a JavaScript string literal within an onclick attribute.
Recommendations Update Roskus Prospero Flow CRM to version 5.3.7 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59232

Affected Products

Prospero Flow Crm