PT-2026-95191 · Unknown · Aureus Erp

·

CVE-2026-93454

·

Published

2026-09-17

·

Updated

2026-09-22

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Aureus ERP versions prior to 1.6.1
Description The Accounting plugin fails to sanitize the Payment Term note field, rendering it as raw HTML. Authenticated users with payment-term create permissions can submit arbitrary JavaScript to the payment-terms endpoint. This script is stored in the database and executes in the browsers of all users who view the affected Payment Term record, leading to a stored Cross-Site Scripting (XSS) condition.
Recommendations Update to a version newer than 1.6.0. Restrict access to the payment-terms endpoint for users who do not strictly require payment-term creation permissions.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93454

Affected Products

Aureus Erp