Cross-site Scripting Vulnerability in Roskus Prospero Flow CRM
CVE-2026-59232

5.3MEDIUM

Key Information:

Vendor

Roskus

Vendor
CVE Published:
31 July 2026

What is CVE-2026-59232?

A cross-site scripting vulnerability exists in Roskus Prospero Flow CRM that allows authenticated users with permissions to create or update leads to inject and execute arbitrary JavaScript code. This occurs when lead names containing malicious HTML markup are rendered without proper escaping, leading to execution within the application’s origin. This issue can potentially compromise user data and the integrity of the application, highlighting the need for secure input handling.

Affected Version(s)

Prospero Flow CRM 0 < 5.3.7

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

k1di3
Cristian Fernández Cornejo
Xoán M. Otero Jorge
Secur0 CNA
Gustavo Novaro
.