Vulnerability Description
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.
Related Weaknesses (CWE)
References
- https://github.com/Roskus/prospero-flow-crm/commit/32efcd5c395ee55119fb9aea502a9
- https://github.com/Roskus/prospero-flow-crm/releases
- https://secur0.com/en/cna/cve-list/cve-2026-59239-stored-xss-in-prospero-flow-cr
FAQ
What is CVE-2026-59239?
CVE-2026-59239 is a documented vulnerability. Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's b...
How severe is CVE-2026-59239?
CVSS scoring is not yet available for CVE-2026-59239. Check NVD for updates.
Is there a patch for CVE-2026-59239?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.