PT-2026-96819 · Unknown · Aureus Erp
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Aureus ERP versions prior to 1.5.0
Description
The software fails to scope message lookups to the current record within the ChatterPanel. This allows authenticated users to access arbitrary messages by submitting sequential message IDs. An attacker can read, edit, delete, or pin messages belonging to other departments or companies, and enumerate all notes stored in the system.
Recommendations
Update to version 1.5.0 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aureus Erp