CVE-2026-59239EPSS p50.1%
CVE-2026-59239CVE-2026-59239
Description
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.
Scoring
| EPSS | 0.67% probability of exploitation · percentile 50.1% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-01 |