Stored Cross-Site Scripting Vulnerability in Roskus Prospero Flow CRM
CVE-2026-59239

8.6HIGH

Key Information:

Vendor

Roskus

Vendor
CVE Published:
27 July 2026

What is CVE-2026-59239?

A vulnerability exists in the email module of Roskus Prospero Flow CRM, allowing a remote, authenticated low-privileged user to inject arbitrary JavaScript code into an email body. This code is stored unsanitized and executed when the recipient, including administrators, opens the email. The exploitation of this flaw can lead to session hijacking and unauthorized access to user accounts, posing a significant security risk to the affected system.

Affected Version(s)

Prospero Flow CRM 1.0.0 < 5.4.4

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Robert Mihaila
Amirreza Fadaeizadeh Bidari
Cristian Fernandez Cornejo
Xoán M. Otero Jorge
Secur0 CNA
Gustavo Novaro
.