PT-2026-96103 · Webkul+1 · Aureus Erp

·

CVE-2026-94387

·

Published

2026-09-21

·

Updated

2026-09-28

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Aureus ERP versions prior to 1.6.0
Description A stored cross-site scripting issue exists in the Chatter field-change log. The system fails to properly escape the old value and new value entries. This allows a user with permissions to edit tracked text fields to inject malicious markup, which then executes in the browser of other users, including administrators, when they view the record's Chatter panel.
Recommendations Update Aureus ERP to version 1.6.0 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94387

Affected Products

Aureus Erp