PT-2026-96103 · Webkul+1 · Aureus Erp
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Aureus ERP versions prior to 1.6.0
Description
A stored cross-site scripting issue exists in the Chatter field-change log. The system fails to properly escape the
old value and new value entries. This allows a user with permissions to edit tracked text fields to inject malicious markup, which then executes in the browser of other users, including administrators, when they view the record's Chatter panel.Recommendations
Update Aureus ERP to version 1.6.0 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aureus Erp