Back

HIGH

Stored XSS in Prospero Flow CRM email body allows administrator account takeover

Published Jul 27, 2026

Description

Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.

Affected products

Remediation

Vendor solution

Upgrade to version 5.4.4 or higher.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Secur0
Published Jul 27, 2026
Updated Jul 27, 2026
Reserved Jul 3, 2026
CISA Vulnrichment
Updated Jul 27, 2026
NVD
Status Deferred
Modified Sep 1, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a