PT-2026-80804 · Roskus · Prospero Flow Crm
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Roskus Prospero Flow CRM versions prior to 5.15.13
Description
An issue exists in the company logo upload feature where the system fails to restrict the upload of dangerous file types. An authenticated user with permissions to create or update companies can upload an SVG document containing an embedded script element, leading to the execution of arbitrary JavaScript within the application origin.
Recommendations
Update Roskus Prospero Flow CRM to version 5.15.13 or later.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prospero Flow Crm