Stored XSS in Prospero Flow CRM email body allows administrator account takeover
Published Jul 27, 2026
8.6
HIGHCVSS 4.0
EPSS 0.67%
Description
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.
Affected products
-
- Version 1.0.0StatusaffectedConstraints<5.4.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Roskus | Prospero Flow CRM | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 5.4.4 or higher.
References (3)
- https://github.com/Roskus/prospero-flow-crm/commit/32efcd5c395ee55119fb9aea502a9d06e4c5adb8 patch
- https://github.com/Roskus/prospero-flow-crm/releases release-notes
- https://secur0.com/en/cna/cve-list/cve-2026-59239-stored-xss-in-prospero-flow-crm-email-body-allows-administrator-account-takeover technical-description
Change history (0)
No recorded changes yet.