CVE-2026-59239
Stored XSS in Prospero Flow CRM email body allows administrator account takeover
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.
| CWE | CWE-79 |
| Vendor | roskus |
| Product | prospero flow crm |
| Published | Jul 27, 2026 |
| Last Updated | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for roskus prospero flow crm
Be the first to know when new unknown vulnerabilities affecting roskus prospero flow crm are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Roskus / Prospero Flow CRM
1.0.0 < 5.4.4
References
github.com: https://github.com/Roskus/prospero-flow-crm/commit/32efcd5c395ee55119fb9aea502a9d06e4c5adb8 github.com: https://github.com/Roskus/prospero-flow-crm/releases secur0.com: https://secur0.com/en/cna/cve-list/cve-2026-59239-stored-xss-in-prospero-flow-crm-email-body-allows-administrator-account-takeover
Credits
Robert Mihaila Amirreza Fadaeizadeh Bidari Cristian Fernandez Cornejo Xoรกn M. Otero Jorge Secur0 CNA Gustavo Novaro