High severityNVD Advisory· Published Jul 27, 2026· Updated Sep 1, 2026
CVE-2026-59239
CVE-2026-59239
Description
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <5.4.4
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.