CVE-2026-59239 – Stored XSS in Prospero Flow CRM email body allows administrator account takeover

​CVE ID :CVE-2026-59239

Published : July 27, 2026, 5:56 p.m. | 27 minutes ago

Description :Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user’s browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.

Severity: 8.6 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More