Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 5.3.7 or higher. The fix was not tagged: the earliest tagged release containing it is v5.5.3.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 31 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in the lead name field, which the view renders through Blade's unescaped output directive and inside a JavaScript string literal in an onclick attribute. | |
| Title | Stored Cross-site Scripting in Prospero Flow CRM lead name field | |
| First Time appeared |
Roskus
Roskus prospero Flow Crm |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:roskus:prospero_flow_crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Roskus
Roskus prospero Flow Crm |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Secur0
Published:
Updated: 2026-07-31T16:57:56.183Z
Reserved: 2026-07-03T11:24:39.241Z
Link: CVE-2026-59232
Updated: 2026-07-31T16:57:17.438Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-31T18:00:07Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')