PT-2026-82753 · Roskus · Prospero Flow Crm

·

CVE-2026-81931

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Roskus Prospero Flow CRM versions prior to 5.16.0
Description An unrestricted file upload issue exists in the product photo upload feature. An authenticated user with the create product permission, such as the Seller role, can execute arbitrary JavaScript within the application origin. The system validates files based on magic bytes (content signatures) and only rejects a specific list of PHP extensions. However, the ProductSaveController::save() function uses the client-supplied extension when saving the file to the public web root. Consequently, a file containing an image header but using an HTML extension can be uploaded to public/asset/upload/product/ and served as text/html, resulting in stored cross-site scripting (XSS), where a malicious script is permanently stored on the server and executed in the browser of users who view the file.
Recommendations Update Roskus Prospero Flow CRM to version 5.16.0 or later.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81931

Affected Products

Prospero Flow Crm