CVE-2026-78337
Description détaillée
Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG document containing an embedded script element.
Dernières Vulnérabilités
CVE-2026-78323
A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.
CVE-2026-78291
Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.
CVE-2026-78290
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
