Unrestricted File Upload Vulnerability in Roskus Prospero Flow CRM
CVE-2026-81931

4.8MEDIUM

Key Information:

Vendor

Roskus

Vendor
CVE Published:
27 August 2026

What is CVE-2026-81931?

The file upload mechanism in Roskus Prospero Flow CRM prior to version 5.16.0 presents an exploit risk by allowing authenticated users with product creation permissions to upload malicious files. The validation process inadequately checks files, only filtering based on content type rather than their extension, enabling harmful scripts to be uploaded as images. Once stored in the web root, these files can execute arbitrary JavaScript, posing significant security threats by enabling first-party stored script execution.

Affected Version(s)

Prospero Flow CRM 0 < 5.16.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrián García López
DarĂ­o Rivas Quero
Secur0 CNA
Gustavo Novaro
.