Beveiligingsadvies

CVE-2026-59239

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-27 17:56:08
Laatst bijgewerkt 2026-07-27 18:31:10
Toegewezen door Secur0
CVSS-score 8.6
Status PUBLISHED

Beschrijving

Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.