CVE-2026-59239 Details
Description
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.
A stored cross-site scripting vulnerability has been identified in the email module of Roskus Prospero Flow CRM, affecting versions prior to 5.4.4. This vulnerability allows remote, authenticated low-privileged users to execute arbitrary JavaScript in the browsers of other users, including administrators. The issue arises because the email body is saved without proper sanitization and is rendered as unescaped HTML when the recipient opens the message. Exploitation of this vulnerability can lead to session hijacking and account takeover.
Users are advised to upgrade to version 5.4.4 or higher.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 27, 2026CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Roskus/prospero-flow-crm/commit/32efcd5c395ee55119fb9aea502a9d06e4c5adb8 | Secur0 | Source CodeVendor |
| https://github.com/Roskus/prospero-flow-crm/releases | Secur0 | Release NotesVendor |
| https://secur0.com/en/cna/cve-list/cve-2026-59239-stored-xss-in-prospero-flow-crm-email-body-allows-administrator-account-takeover | Secur0 | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Secur0 |
Affected Products
| Product | Versions |
|---|---|
| Roskus Prospero Flow CRM | < 5.4.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 27, 2026 | New CVE Received | Secur0 |
Volerion