CVE-2026-81931
Last modified
CVE-2026-81931 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. Unrestricted Upload of File with Dangerous Type in the product photo upload in Roskus Prospero Flow CRM before 5.16.0 allows an authenticated user holding the create product permission (routine Seller role) to execute arbitrary JavaScript in the application origin. The photo validation rule classifies the file only by its content (magic bytes) and rejects only a fixed list of PHP extensions, while ProductSaveController::save() names the stored file using the client-supplied extension and copies it into the public web root. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Unrestricted Upload of File with Dangerous Type in the product photo upload in Roskus Prospero Flow CRM before 5.16.0 allows an authenticated user holding the create product permission (routine Seller role) to execute arbitrary JavaScript in the application origin. The photo validation rule classifies the file only by its content (magic bytes) and rejects only a fixed list of PHP extensions, while ProductSaveController::save() names the stored file using the client-supplied extension and copies it into the public web root. A file that begins with an image header and carries an HTML extension passes validation, is stored under public/asset/upload/product/, and is served with a text/html content type, turning the upload into first-party stored script execution.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Roskus | Prospero Flow CRM | < 5.16.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-81931?
How severe is CVE-2026-81931?
How do I fix CVE-2026-81931?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81892EasyAdmin is a fast and modern admin generator for Symfony a…8.1
- CVE-2026-81893A flaw was found in gdk-pixbuf. When loading a specially cra…4.7
- CVE-2026-8190A vulnerability was determined in Wavlink NU516U1 M16U1_V240…8.8
- CVE-2026-8191A vulnerability was identified in Wavlink NU516U1 M16U1_V240…8.8
- CVE-2026-8192A security flaw has been discovered in Wavlink NU516U1 M16U1…8.8
- CVE-2026-8193A weakness has been identified in Akaunting 3.1.21. This iss…6.3
- CVE-2026-81934Redis contains a use-after-free vulnerability in the 'tlsPro…7.1
- CVE-2026-8194A security vulnerability has been detected in osTicket up to…4.3
- CVE-2026-8195A vulnerability was detected in JeecgBoot up to 3.9.1. The a…4.3
- CVE-2026-8196A flaw has been found in JeecgBoot 3.9.1. The impacted eleme…3.7
- CVE-2026-8197Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via…4.8
- CVE-2026-8198The Activity Logs, User Activity Tracking, Multisite Activit…5.3
Are you affected by CVE-2026-81931?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
