CVE-2026-59239
8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:L/SA:N
Summary
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Roskus | Prospero Flow CRM | 1.0.0 < 5.4.4 | affected |
Weaknesses
- CWE-79: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
- https://github.com/Roskus/prospero-flow-crm/commit/32efcd5c395ee55119fb9aea502a9d06e4c5adb8
- https://github.com/Roskus/prospero-flow-crm/releases
- https://secur0.com/en/cna/cve-list/cve-2026-59239-stored-xss-in-prospero-flow-crm-email-body-allows-administrator-account-takeover
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.