CVE-2026-78337
MEDIUM
4,8
Source: 4daa8cea-433a-44bd-9456-53b127fc289a
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: active
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.
434
Unrestricted Upload of File with Dangerous Type
DraftCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Potential Impacts:
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages:
ASP.NET, PHP, Not Language-Specific
Technologies:
Web Server, AI/ML
https://github.com/Roskus/prospero-flow-crm/commit/aaa4fc76bf039d5011884b86b8f2…
https://secur0.com/en/cna/cve-list/cve-2026-78337-unrestricted-upload-company-l…