CVE-2026-78337
Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVG
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.
| CWE | CWE-434 |
| Vendor | roskus |
| Product | prospero flow crm |
| Published | Aug 24, 2026 |
| Last Updated | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for roskus prospero flow crm
Be the first to know when new unknown vulnerabilities affecting roskus prospero flow crm are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Roskus / Prospero Flow CRM
0 < 5.15.13
References
Credits
Adrián García López Darío Rivas Quero Xoán M. Otero Jorge Secur0 CNA Gustavo Novaro