Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wpjv-rrg6-52x9

Опубликовано: 27 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6

Описание

Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.

Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.

EPSS

Процентиль: 31%
0.00383
Низкий

8.6 High

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
около 1 месяца назад

Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.

EPSS

Процентиль: 31%
0.00383
Низкий

8.6 High

CVSS4

Дефекты

CWE-79