VULNERABILITY INTELLIGENCE
CVE-2026-59239
CVSS score8.6 HIGH
EPSS probability0.67%
CISA KEVNot currently listed
Published2026-07-27
Last modified2026-09-01
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:L/SA:N
Description
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.
Weakness classification
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')