CVE-2026-78337

Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-24 11:16

Updated : 2026-09-01 20:52


NVD link : CVE-2026-78337

Mitre link : CVE-2026-78337

CVE.ORG link : CVE-2026-78337


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type