Description
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.
Published: 2026-08-24
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade to 5.15.13 or later from the main branch; no tag carries the fix. Review and remove existing SVG files under storage/app/public/company/

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.
Title Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVG
First Time appeared Roskus
Roskus prospero Flow Crm
Weaknesses CWE-434
CPEs cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:*
Vendors & Products Roskus
Roskus prospero Flow Crm
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}


Subscriptions

Roskus Prospero Flow Crm
cve-icon MITRE

Status: PUBLISHED

Assigner: Secur0

Published:

Updated: 2026-08-24T11:57:57.795Z

Reserved: 2026-08-24T10:43:34.502Z

Link: CVE-2026-78337

cve-icon Vulnrichment

Updated: 2026-08-24T11:57:54.669Z

cve-icon NVD

Status : Received

Published: 2026-08-24T11:16:41.203

Modified: 2026-08-24T12:16:56.427

Link: CVE-2026-78337

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type