PT-2026-82753 · Roskus · Prospero Flow Crm
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Roskus Prospero Flow CRM versions prior to 5.16.0
Description
An unrestricted file upload issue exists in the product photo upload feature. An authenticated user with the create product permission, such as the Seller role, can execute arbitrary JavaScript within the application origin. The system validates files based on magic bytes (content signatures) and only rejects a specific list of PHP extensions. However, the
ProductSaveController::save() function uses the client-supplied extension when saving the file to the public web root. Consequently, a file containing an image header but using an HTML extension can be uploaded to public/asset/upload/product/ and served as text/html, resulting in stored cross-site scripting (XSS), where a malicious script is permanently stored on the server and executed in the browser of users who view the file.Recommendations
Update Roskus Prospero Flow CRM to version 5.16.0 or later.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prospero Flow Crm