CVE-2026-59239

Roskus · Prospero Flow CRM

A stored Cross-site Scripting vulnerability in the email module of Roskus Prospero Flow CRM allows attackers to inject malicious scripts, potentially leading to administrator account takeover.

Executive summary

Roskus Prospero Flow CRM is vulnerable to a stored Cross-site Scripting attack that could enable an attacker to compromise administrative accounts.

Vulnerability

The vulnerability exists in the email module, where insufficient neutralization of user-supplied input allows for the execution of arbitrary scripts. This flaw is exploitable by an unauthenticated attacker, though it requires user interaction, such as an administrator viewing a malicious email.

Business impact

The ability to perform stored Cross-site Scripting in a CRM environment carries a high risk of sensitive data exposure and full account takeover. With a CVSS score of 8.6, this vulnerability could allow an attacker to gain elevated privileges, access customer databases, or exfiltrate private communications. Unauthorized access to a CRM platform can lead to severe reputational damage and compliance violations.

Remediation

Immediate Action: Upgrade to version 5.4.4 or higher immediately to apply the necessary input sanitization patches.

Proactive Monitoring: Review application logs for suspicious script tags or encoded payloads within the email module. Audit administrator activity for unusual actions following the deployment of the update.

Compensating Controls: Deploy a Web Application Firewall with rules configured to detect and block common XSS payloads directed at the CRM web interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for administrative account takeover, this vulnerability should be treated with high priority. Organizations using Prospero Flow CRM must verify their current version and schedule an update to 5.4.4 as soon as possible to mitigate the risk of unauthorized access.