CVE-2026-78337
4.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Summary
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Roskus | Prospero Flow CRM | 0 < 5.15.13 | affected |
Weaknesses
- CWE-434: CWE-434 Unrestricted upload of file with dangerous type
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/Roskus/prospero-flow-crm/commit/aaa4fc76bf039d5011884b86b8f29ddd50d17b17
- https://secur0.com/en/cna/cve-list/cve-2026-78337-unrestricted-upload-company-logo-svg-xss
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.