Description
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.
Published: 2026-08-24
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via SVG uploads
Action: Patch
AI Analysis

Impact

The vulnerability permits an authenticated user with create or update company permissions to upload a file containing SVG content. If the SVG includes a script element, the JavaScript executes in the context of the application origin whenever the uploaded logo is displayed, allowing the attacker to run arbitrary script on a victim’s browser.

Affected Systems

Roskus Prospero Flow CRM versions prior to 5.15.13 are affected. Users of earlier releases must upgrade to 5.15.13 or later, or delete any existing SVG files from storage/app/public/company to mitigate the risk.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity. EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated account with specific company permissions, so it can only be leveraged by insiders or compromised credentials. No publicly documented remote exploitation path exists, reducing the likelihood of widespread attacks in environments lacking such permissions.

Generated by OpenCVE AI on August 24, 2026 at 12:54 UTC.

Remediation

Vendor Solution

Upgrade to 5.15.13 or later from the main branch; no tag carries the fix. Review and remove existing SVG files under storage/app/public/company/


OpenCVE Recommended Actions

  • Upgrade Prospero Flow CRM to version 5.15.13 or later to receive the patched upload validation logic.
  • Remove any SVG files already stored in storage/app/public/company to eliminate existing malicious assets.
  • As an interim measure, block SVG uploads or restrict uploads to safe image file types only to prevent new vulnerable files from being stored.

Generated by OpenCVE AI on August 24, 2026 at 12:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.
Title Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVG
First Time appeared Roskus
Roskus prospero Flow Crm
Weaknesses CWE-434
CPEs cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:*
Vendors & Products Roskus
Roskus prospero Flow Crm
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}


Subscriptions

Roskus Prospero Flow Crm
cve-icon MITRE

Status: PUBLISHED

Assigner: Secur0

Published:

Updated: 2026-08-24T11:57:57.795Z

Reserved: 2026-08-24T10:43:34.502Z

Link: CVE-2026-78337

cve-icon Vulnrichment

Updated: 2026-08-24T11:57:54.669Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T11:16:41.203

Modified: 2026-09-01T20:52:27.110

Link: CVE-2026-78337

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T13:45:04Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type