CVE-2026-81931 | Roskus Prospero Flow CRM up to 5.15.x Photo Upload product save unrestricted upload

SecurityVulns

A vulnerability marked as critical has been reported in Roskus Prospero Flow CRM up to 5.15.x. This affects the function ProductSaveController::save of the file public/asset/upload/product of the component Photo Upload. Performing a manipulation results in unrestricted upload.

This vulnerability was named CVE-2026-81931. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More