CVE-2026-59239
Roskus · Prospero Flow CRM
A stored Cross-site Scripting vulnerability in the email module of Roskus Prospero Flow CRM allows attackers to inject malicious scripts, potentially leading to administrator account takeover.
Executive summary
Roskus Prospero Flow CRM is vulnerable to a stored Cross-site Scripting attack that could enable an attacker to compromise administrative accounts.
Vulnerability
The vulnerability exists in the email module, where insufficient neutralization of user-supplied input allows for the execution of arbitrary scripts. This flaw is exploitable by an unauthenticated attacker, though it requires user interaction, such as an administrator viewing a malicious email.
Business impact
The ability to perform stored Cross-site Scripting in a CRM environment carries a high risk of sensitive data exposure and full account takeover. With a CVSS score of 8.6, this vulnerability could allow an attacker to gain elevated privileges, access customer databases, or exfiltrate private communications. Unauthorized access to a CRM platform can lead to severe reputational damage and compliance violations.
Remediation
Immediate Action: Upgrade to version 5.4.4 or higher immediately to apply the necessary input sanitization patches.
Proactive Monitoring: Review application logs for suspicious script tags or encoded payloads within the email module. Audit administrator activity for unusual actions following the deployment of the update.
Compensating Controls: Deploy a Web Application Firewall with rules configured to detect and block common XSS payloads directed at the CRM web interface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for administrative account takeover, this vulnerability should be treated with high priority. Organizations using Prospero Flow CRM must verify their current version and schedule an update to 5.4.4 as soon as possible to mitigate the risk of unauthorized access.