CVE-2026-94387
5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Summary
Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can inject malicious markup that executes when other users, including administrators, view the record's Chatter panel.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| aureuserp | aureuserp | 0 < 1.6.0 | affected |
| aureuserp | aureuserp | 1.6.0 | unaffected |
Weaknesses
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/aureuserp/aureuserp/commit/57cf5cf4c98d82a0ad89003402f27823fbe1e27c
- https://github.com/aureuserp/aureuserp/pull/1465
- https://github.com/aureuserp/aureuserp/blob/v1.5.0/plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php#L165
- https://github.com/aureuserp/aureuserp/blob/v1.5.0/plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php#L182
- https://hackmd.io/@leediay/stored-xss-aureuserp-chatter
- https://github.com/aureuserp/aureuserp/releases/tag/v1.6.0
- https://github.com/aureuserp/aureuserp
- https://www.vulncheck.com/advisories/aureus-erp-before-1.6.0-stored-xss-via-chatter-field-change-log
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.