Impact
The vulnerability permits an authenticated user with create or update company permissions to upload a file containing SVG content. If the SVG includes a script element, the JavaScript executes in the context of the application origin whenever the uploaded logo is displayed, allowing the attacker to run arbitrary script on a victim’s browser.
Affected Systems
Roskus Prospero Flow CRM versions prior to 5.15.13 are affected. Users of earlier releases must upgrade to 5.15.13 or later, or delete any existing SVG files from storage/app/public/company to mitigate the risk.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated account with specific company permissions, so it can only be leveraged by insiders or compromised credentials. No publicly documented remote exploitation path exists, reducing the likelihood of widespread attacks in environments lacking such permissions.
OpenCVE Enrichment