CVE-2026-78337

Published: Ago 24, 2026 Last Modified: Ago 24, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 4,8
Source: 4daa8cea-433a-44bd-9456-53b127fc289a
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: active
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.

434

Unrestricted Upload of File with Dangerous Type

Draft
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability
Potential Impacts:
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages: ASP.NET, PHP, Not Language-Specific
Technologies: Web Server, AI/ML
View CWE Details
https://github.com/Roskus/prospero-flow-crm/commit/aaa4fc76bf039d5011884b86b8f2…
https://secur0.com/en/cna/cve-list/cve-2026-78337-unrestricted-upload-company-l…